CRITICAL Introduced in 5.11
sctp UdpTunnel UAF
CVE-2026-68161
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.5HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: sctp: close UDP tunnel sockets during netns teardown proc_sctp_do_udp_port() starts per-net SCTP UDP tunneling sockets when net.sctp.udp_port is set, and stops/restarts them when the sysctl value changes. The netns exit path does not stop these sockets, so a namespace can be torn down while its SCTP UDP tunnel sockets are still installed. Close the UDP tunnel sockets from sctp_ctrlsock_exit() after unregistering the per-net sysctl table. This prevents new sysctl writes from racing in while the sockets are being released, and closes the sockets before the control socket is destroyed.
02KernelScan AI Analysis
Risk summary
A local unprivileged attacker who can create a user namespace can trigger a use-after-free by setting the SCTP UDP tunneling sysctl and then tearing down the namespace. The UDP tunnel sockets are not cleaned up during namespace exit, leaving dangling socket references after namespace data structures are freed. This can lead to kernel memory corruption, privilege escalation, or denial of service.
Vulnerability analysis
The SCTP UDP tunneling feature creates per-namespace UDP sockets when a sysctl enables UDP tunneling, but the network namespace exit path never closes these sockets. When a namespace is torn down, the UDP tunnel sockets remain active and can continue to be referenced after the namespace's data structures have been freed, resulting in a use-after-free. The fix closes the UDP tunnel sockets during namespace exit, after first unregistering the sysctl interface so new settings cannot race with the socket release. This vulnerability is reachable locally by any unprivileged user who can create a user namespace, because obtaining network-admin capability inside that namespace is enough to enable the SCTP UDP tunnel and trigger the buggy teardown path.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.6 | 5.11 | 6.6.151 | c6eb2d615210 |
| 6.12 | 5.11 | 6.12.101 | 8ff78591d309 |
| 6.18 | 5.11 | 6.18.42 | 3bf0e349cbb4 |
| 7.1 | 5.11 | 7.1.6 | 37ff9794be48 |
| mainline | 5.11 | 7.2-rc5 | ffb2bd7ade36 |