---
id: CVE-2026-89476
title: >-
  kernel: sctp: fix stream->outcnt underflow on duplicate RECONF responses
  (CVE-2026-89476)
summary: >-
  A flaw was found in the Linux kernel's Stream Control Transmission Protocol
  (SCTP) implementation. A remote attacker could exploit this by sending
  specially crafted duplicate RECONF responses. This action can cause an
  underflow in the `str…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-191
vendor: Red Hat
product: Red Hat Enterprise Linux 9
affected:
  - enterprise_linux 10
  - enterprise_linux 8
  - enterprise_linux 9
  - openshift_container_platform 4
published: '2026-09-11'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T15:20:33+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89476.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89476.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89476'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532035'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89476'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89476'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89476.mbox
  - url: 'https://git.kernel.org/stable/c/041f7df5a929d3e7435dd8387e8ea17f2d412b7d'
  - url: 'https://git.kernel.org/stable/c/59f61c39cb99ee1737bd742a20094fe5653389bb'
  - url: 'https://git.kernel.org/stable/c/793519e343867ee9a3e84f6cac07f81f2aec7b5d'
  - url: 'https://git.kernel.org/stable/c/092acd3c55a4077b00489064615d8d2d898daf91'
  - url: 'https://git.kernel.org/stable/c/2d867663c563e8009257b9edf9c8ec75d9bbf19a'
  - url: 'https://git.kernel.org/stable/c/d02a5794c3deedcb8476d017fcee2b7aaedab2e1'
  - url: 'https://git.kernel.org/stable/c/8320cbd81bc21a1ca6ebdf70ad610ebc5ef1bd68'
  - url: 'https://git.kernel.org/stable/c/3faf13aff243ca9f78d08b1a2956ef5a6fc77b6e'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00686
epssPercentile: 0.51256
scores:
  vendor: 7
  cna: 7.5
ingestedAt: '2026-09-14T15:23:07.453Z'
---

## Overview

A flaw was found in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation. A remote attacker could exploit this by sending specially crafted duplicate RECONF responses. This action can cause an underflow in the `stream->outcnt` counter, potentially leading to unexpected system behavior or a denial of service (DoS) condition.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89476.json)

**kernel: sctp: fix stream->outcnt underflow on duplicate RECONF responses** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.

Affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

No fix planned:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

Not affected:

- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7

## Remediation

Affected
