HIGH
sctp AuthEnable UAF
CVE-2026-68162
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.7HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns teardown proc_sctp_do_auth() updates the SCTP control socket after changing net.sctp.auth_enable. The handler gets the per-net SCTP state from ctl->data, so an already opened sysctl file can still target a network namespace while that namespace is being torn down. SCTP previously registered its per-net sysctls from sctp_defaults_init(), while the control socket is created later from sctp_ctrlsock_init(). This exposed a window during initialization where auth_enable was writable before net->sctp.ctl_sock existed, and a teardown window where auth_enable stayed writable after inet_ctl_sock_destroy() had released the control socket. Move the per-net SCTP sysctl registration into sctp_ctrlsock_init() after sctp_ctl_sock_init() succeeds, and unregister the sysctl table before destroying the control socket in sctp_ctrlsock_exit(). If sysctl registration fails after the control socket was created, destroy the control socket in the same init path. Make sctp_sysctl_net_unregister() tolerate a missing header and clear the saved pointer so init-error and exit paths can safely share the unregister helper.
02KernelScan AI Analysis
Risk summary
An unprivileged local user who can create a network namespace (via user namespaces) can race a write to the SCTP auth_enable sysctl against network namespace teardown, triggering a use-after-free on the SCTP control socket. This can lead to kernel memory corruption, potentially enabling container or namespace escape, privilege escalation, or denial of service via kernel panic.
Vulnerability analysis
The kernel's SCTP authentication setting can be changed through a per-network-namespace sysctl. This interface is supposed to update the namespace's control socket, but if the namespace is being destroyed, the socket can be freed while the sysctl file is still open. Writing to the file at that point accesses the freed socket, causing memory corruption. The fix ensures the sysctl registration stays within the lifetime of the control socket, so the interface disappears before the socket is destroyed. A local unprivileged user who can create network namespaces, such as through user namespaces, can hold the sysctl open and trigger the race.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.4 | 5.4.290 | 5.4.292 | 19573dcddb88 |
| 5.10 | 5.10.234 | 5.10.266 | ceb7190b5c87 |
| 5.15 | 5.15.177 | 5.15.217 | fd66854a2266 |
| 6.1 | 6.1.125 | 6.1.184 | 158f3cc332dc |
| 6.12 | 6.12.10 | 6.12.101 | 626bda8cfe43 |
| 6.18 | — | 6.18.42 | be6aae9d1b91 |
| 7.1 | — | 7.1.6 | a50e73488e0b |
| mainline | — | 7.2 | f8d5e7846025 |
| 6.6 | 6.6.72 | 6.6.151 | 66700c071967 |