Threat Advisory

Linux SCTP Privilege Escalation Flaw Allows Kernel Crash and Denial of Service

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A Linux kernel vulnerability affecting Unknown versions The flaw dates back to code added in October 2017, identified as CVE-2026-52929 with a CVSS score of 9.8, allows an attacker to exploit the SCTP stream handling component in the kernel's network stack, resulting in privilege escalation or denial-of-service conditions. The flaw, which dates back to code added in October 2017, affects many long-lived kernel branches and can be exploited by reusing stale stream metadata to cause a null pointer dereference. This vulnerability has significant business impact as SCTP ships in most mainstream Linux distributions, affecting a wide range of servers and workstations. The attack vector is remote, allowing an attacker to exploit the flaw from a distance.

RECOMMENDATION:

We recommend you to update Linux to version 0cd2dc6dce8ca47212cd306ccd52eb315ef3cf85.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A Linux kernel vulnerability affecting Unknown versions The flaw dates back to code added in October 2017, identified as CVE-2026-52929 with a CVSS score of 9.8, allows an attacker to exploit the SCTP stream handling component in the kernel's network stack, resulting in privilege escalation or denial-of-service conditions. The flaw, which dates back to code added in October 2017, affects many long-lived kernel branches and can be exploited by reusing stale stream metadata to cause a null pointer dereference. This vulnerability has significant business impact as SCTP ships in most mainstream Linux distributions, affecting a wide range of servers and workstations. The attack vector is remote, allowing an attacker to exploit the flaw from a distance.

RECOMMENDATION:

We recommend you to update Linux to version 0cd2dc6dce8ca47212cd306ccd52eb315ef3cf85.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu