sctp: hold socket lock when dumping endpoints in sctp_diag
Summary
| CVE | CVE-2026-72447 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 06:22:18 UTC |
| Updated | 2026-08-17 06:19:12 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: sctp: hold socket lock when dumping endpoints in sctp_diag SCTP_DIAG endpoint dumping was traversing endpoint address lists without holding lock_sock(), while those lists could change concurrently via socket operations (e.g., bindx changes). This creates a race where nla_reserve() counts addresses under RCU protection, but the subsequent copy may see fewer entries, potentially leaking uninitialized memory to userspace. Fix this by: - Taking a reference on each endpoint during hash traversal - Moving socket operations (lock_sock()) outside read_lock_bh() - Serializing address list access during dump - Reworking sctp_for_each_endpoint() to support restart-based traversal with (net, pos) tracking Also: - Add WARN_ON_ONCE() for inconsistent address counts - Fix idiag_states filtering for LISTEN vs association cases - Skip dumping endpoints being freed (ep->base.dead) - Move dump position tracking into iterator, removing cb->args[4] and its comment for sctp_ep_dump()., - Update the comment for cb->args[4] and remove the comment for unused cb->args[5] for sctp_sock_dump(). Note: traversal is restart-based and may re-scan buckets multiple times, but this is acceptable due to small bucket sizes and required to support sleeping-safe callbacks. This issue was reported by Nico Yip (@_cyeaa_) working with TrendAI Zero Day Initiative. |
Risk And Classification
EPSS: 0.002200000 probability, percentile 0.127040000 (date 2026-08-17)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 8f840e47f190cbe61a96945c13e9551048d42cef f98c294a9369b6fe89e652c06357ee594be4dfa2 git | Not specified |
| CNA | Linux | Linux | affected 8f840e47f190cbe61a96945c13e9551048d42cef 8b38e3dcfde3077dbc03eb8ef88e03cc19f70b8a git | Not specified |
| CNA | Linux | Linux | affected 8f840e47f190cbe61a96945c13e9551048d42cef ec3c2d59a192e17e1014ba71afc368ba162ecac3 git | Not specified |
| CNA | Linux | Linux | affected 8f840e47f190cbe61a96945c13e9551048d42cef 722576aba0a6d9423714550b1c03239b0f0def77 git | Not specified |
| CNA | Linux | Linux | affected 8f840e47f190cbe61a96945c13e9551048d42cef abe7f8828e6ac8be858870c2bf836258844f97d5 git | Not specified |
| CNA | Linux | Linux | affected 8f840e47f190cbe61a96945c13e9551048d42cef 207bb4ce8fe7de961ae7bb33569ad2cd61f44954 git | Not specified |
| CNA | Linux | Linux | affected 8f840e47f190cbe61a96945c13e9551048d42cef f09a245f33e567b604efa1960b7a2d25dd9c8713 git | Not specified |
| CNA | Linux | Linux | affected 8f840e47f190cbe61a96945c13e9551048d42cef 7d8297e26b4e20b5d1c3c3fe51fe81a1c7fbc823 git | Not specified |
| CNA | Linux | Linux | affected 4.7 | Not specified |
| CNA | Linux | Linux | unaffected 4.7 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.261 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.212 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.178 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.145 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.97 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.40 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.5 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/ec3c2d59a192e17e1014ba71afc368ba162ecac3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f09a245f33e567b604efa1960b7a2d25dd9c8713 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/722576aba0a6d9423714550b1c03239b0f0def77 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/7d8297e26b4e20b5d1c3c3fe51fe81a1c7fbc823 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/207bb4ce8fe7de961ae7bb33569ad2cd61f44954 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/abe7f8828e6ac8be858870c2bf836258844f97d5 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/8b38e3dcfde3077dbc03eb8ef88e03cc19f70b8a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f98c294a9369b6fe89e652c06357ee594be4dfa2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.