CVE-2026-63971
CVE CVE-2026-63971EUVD EUVD-2026-45744Published 2026-07-19T14:55:57.000ZLast changed 2026-08-05T12:37:42.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: sctp: fix race between sctp_wait_for_connect and peeloff sctp_wait_for_connect() drops and re-acquires the socket lock while waiting for the association to reach ESTABLISHED state. During this window, another thread can peeloff the association to a new socket via getsockopt(SCTP_SOCKOPT_PEELOFF), changing asoc->base.sk. After re-acquiring the old socket lock, sctp_wait_for_connect() returns success without noticing the migration — the caller then accesses the association under the wrong lock in sctp_datamsg_from_user(). Add the same sk != asoc->base.sk check that sctp_wait_for_sndbuf() already has, returning an error if the association was migrated while we slept.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 668c9beb9020d5834ee9e43c208190a07d2b1928 <bcfeac79af740735ace44008b4a11b8e5add20f5; patch: 6.12.93; patch: 6.1.176; 668c9beb9020d5834ee9e43c208190a07d2b1928 <f14fe6395a8b3d961a61e138ad7b36ba3626dd4e; 668c9beb9020d5834ee9e43c208190a07d2b1928 <634a9af8a26a84d8b0d7b3b643204b344b42d9fb; patch: 6.18.35; 668c9beb9020d5834ee9e43c208190a07d2b1928 <6140cfa721451fa6e18e134e709703c2bf34d0fb; 668c9beb9020d5834ee9e43c208190a07d2b1928 <68667ee4c7dadf7f63167234e2a1af09b3f7874e; patch: 7.1; patch: 5.15.210; patch: 5.10.259; patch: 0; 668c9beb9020d5834ee9e43c208190a07d2b1928 <8e9b56051d24540cfbf39194618708c4a7633549; patch: 7.0.12; patch: 6.6.143; 668c9beb9020d5834ee9e43c208190a07d2b1928 <0e0d5bc76fd4267a71334fcc8f1a5fbcf997845d; 4.16; 668c9beb9020d5834ee9e43c208190a07d2b1928 <7d2038d4b80166f7bead8d07eba3b97405816c21
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.