---
id: CVE-2026-64564
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  sctp: don't free the ASCONF's own transport in DEL-IP processing

  sctp_process_asconf() caches the transport the ASCONF chunk is processed
  against in asconf->transport …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  sctp: don't free the ASCONF's own transport in DEL-IP processing

  sctp_process_asconf() caches the transport the ASCONF chunk is processed
  against in asconf->transport …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
published: '2026-08-04'
updated: '2026-08-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64564'
references:
  - url: 'https://git.kernel.org/stable/c/74e8f3e7114f0e26d1b2c4c048044db9fcc27603'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/85aca407c560aba81b5ce9d3d6cf94c74077d19b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9b2854f86f0b56e9027d68e7a3fc909d1a9b566f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d136b29bf91dd8e3161281b87de597b7311d9462'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fedeb4468987bcaff85fe3061de5ae052d414740'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'http://www.openwall.com/lists/oss-security/2026/08/06/13'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/08/06/3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/08/06/4'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/08/07/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/08/07/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/08/07/8'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-64564.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-64564'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2510890'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-64564'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64564'
  - url: >-
      https://lore.kernel.org/linux-cve-announce/2026080404-CVE-2026-64564-6762@gregkh/T
  - url: 'https://access.redhat.com/errata/RHSA-2026:69089'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69837'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70290'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70308'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70482'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69908'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70484'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71213'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69874'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69906'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71016'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70483'
tags:
  - nvd
  - exploit-available
  - csaf
  - vex
  - red-hat
  - score-dispute
epss: 0.01482
epssPercentile: 0.72842
ingestedAt: '2026-08-08T19:28:35.066Z'
exploits:
  github: 5
  githubRepos:
    - 'https://github.com/ethanolgolf/CVE-2026-64564'
    - 'https://github.com/HackSpeak/CVE-2026-64564'
    - 'https://github.com/suominen/sctphantom'
  checkedAt: '2026-09-24T07:53:12.029Z'
exploitAvailable: true
vendor: Red Hat
product: Red Hat Enterprise Linux 9
affected:
  - enterprise_linux 10
  - enterprise_linux 6
  - enterprise_linux 7
  - enterprise_linux 8
  - enterprise_linux 9
  - openshift_container_platform 4
cwe:
  - CWE-825
scores:
  nvd: 9.8
  vendor: 7.8
patched:
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_baseos_eus_v_10_0
  - enterprise_linux_codeready_linux_builder_eus_v_10_0
  - enterprise_linux_real_time_for_nfv_eus_v_10_0
  - enterprise_linux_real_time_eus_v_10_0
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

sctp: don't free the ASCONF's own transport in DEL-IP processing

sctp_process_asconf() caches the transport the ASCONF chunk is processed
against in asconf->transport (== chunk->transport, set once in sctp_rcv()).
For an ASCONF located through its Address Parameter by
__sctp_rcv_asconf_lookup(), that cached transport corresponds to the
Address Parameter, which need not be the packet's source address.

sctp_process_asconf_param() rejects a DEL-IP for the packet source address
(ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport.
A single ASCONF can therefore carry, in order:

    [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]

where L differs from the source. The DEL-IP for L passes the D8 check and
calls sctp_assoc_rm_peer() on the transport that asconf->transport still
points at, freeing it (RCU-deferred). The following wildcard DEL-IP then
reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and
sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed
transport (->ipaddr, ->state) and plants the dangling pointer into
asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping
only the pointer that is no longer on the list, removes every real
transport, leaving the association with a transport_count of 0 and
primary_path/active_path pointing at freed memory.

Reject a DEL-IP that targets the transport the ASCONF is being processed
against, mirroring the existing source-address guard, so the wildcard
branch can never reuse a freed transport.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-64564.json)
- **RHSA-2026:69089** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux BaseOS EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0), Red Hat Enterprise Linux Real Time for NFV EUS (v. 10.0), Red Hat Enterprise Linux Real Time EUS (v. 10.0) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69089)
- **RHSA-2026:69837** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69837)
- **RHSA-2026:70290** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70290)
- **RHSA-2026:70308** · Red Hat · fixed in: Red Hat Enterprise Linux for Real Time (v. 7 ELS) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70308)
- **RHSA-2026:70482** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux BaseOS E4S (v.9.2) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70482)
- **RHSA-2026:69908** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4), Red Hat Enterprise Linux BaseOS E4S (v.9.4), Red Hat Enterprise Linux Real Time for NFV E4S (v.9.4), Red Hat Enterprise Linux Real Time E4S (v.9.4) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69908)
- **RHSA-2026:70484** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat Enterprise Linux BaseOS EUS (v.9.6), Red Hat CodeReady Linux Builder EUS (v.9.6), Red Hat Enterprise Linux Real Time for NFV EUS (v.9.6), Red Hat Enterprise Linux Real Time EUS (v.9.6) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70484)
- **RHSA-2026:71213** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71213)
- **RHSA-2026:69874** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS AUS (v.8.4), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69874)
- **RHSA-2026:69906** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS AUS (v.8.6), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69906)
- **RHSA-2026:71016** · Red Hat · fixed in: Red Hat Enterprise Linux NFV (v. 8), Red Hat Enterprise Linux RT (v. 8) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71016)
