CVE-2026-74469
sctp: prevent peer transport count overflow
Description
In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport count overflow sctp_assoc_add_peer() increments the association's 16-bit transport_count for every new unique peer. Adding the 65,536th transport wraps the count to zero. SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload, then copies one sockaddr_storage for every entry in transport_addr_list. After the wrap, a diagnostic dump reserves an empty payload and writes 8 MiB of peer addresses past the skb tail. Reject a new unique peer when transport_count has reached U16_MAX. Perform the check after the existing-peer lookup so a duplicate address continues to return its existing transport at the limit.
INFO
Published Date :
Aug. 15, 2026, 1:17 p.m.
Last Modified :
Aug. 19, 2026, 5:21 p.m.
Remotely Exploit :
Yes !
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Apply the patch for sctp: prevent peer transport count overflow.
- Update the Linux kernel to a fixed version.
- Reject new peers when transport count reaches U16_MAX.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-74469.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-74469 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-74469
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-74469 vulnerability anywhere in the article.
-
The Hacker News
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence o ... Read more
-
The Hacker News
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all fo ... Read more
The following table lists the changes that have been made to the
CVE-2026-74469 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 19, 2026
Action Type Old Value New Value Added Reference https://git.kernel.org/stable/c/80f48523a0fe42db2e7375dff4e38a25c117090a Added Reference https://git.kernel.org/stable/c/b453e00da1211e997b82743d28af7714c59c05c8 Added Reference https://git.kernel.org/stable/c/dfea32dd76f390e3155177b0038cc47b01386198 Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '546221b86ceeba0d8fec92d46a0604bb7b62be07', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '09e722030e8148ba4ed1e42c6b2ea57bda9f9895', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '4ba5bf7ed50f235ea4581de8e7a0002f4ed287b0', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '6201cd1d70f1670c5b31ac506e7ab2fa7b8e7f75', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': 'bd0e9289e2642f6a5c54faad304ce0f41e926d22', 'versionType': 'git'}], 'programFiles': ['net/sctp/associola.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.7'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.7', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.151', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.103', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.44', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.8', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/associola.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': 'b453e00da1211e997b82743d28af7714c59c05c8', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': 'dfea32dd76f390e3155177b0038cc47b01386198', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '80f48523a0fe42db2e7375dff4e38a25c117090a', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '546221b86ceeba0d8fec92d46a0604bb7b62be07', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '09e722030e8148ba4ed1e42c6b2ea57bda9f9895', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '4ba5bf7ed50f235ea4581de8e7a0002f4ed287b0', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '6201cd1d70f1670c5b31ac506e7ab2fa7b8e7f75', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': 'bd0e9289e2642f6a5c54faad304ce0f41e926d22', 'versionType': 'git'}], 'programFiles': ['net/sctp/associola.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.7'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.7', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.265', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.216', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.183', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.151', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.103', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.44', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.8', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/associola.c'], 'defaultStatus': 'affected'}] -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 17, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '546221b86ceeba0d8fec92d46a0604bb7b62be07', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '09e722030e8148ba4ed1e42c6b2ea57bda9f9895', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '4ba5bf7ed50f235ea4581de8e7a0002f4ed287b0', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '6201cd1d70f1670c5b31ac506e7ab2fa7b8e7f75', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': 'bd0e9289e2642f6a5c54faad304ce0f41e926d22', 'versionType': 'git'}], 'programFiles': ['net/sctp/associola.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.7'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.7', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.151', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.103', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.44', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.8', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc6', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/associola.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '546221b86ceeba0d8fec92d46a0604bb7b62be07', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '09e722030e8148ba4ed1e42c6b2ea57bda9f9895', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '4ba5bf7ed50f235ea4581de8e7a0002f4ed287b0', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '6201cd1d70f1670c5b31ac506e7ab2fa7b8e7f75', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': 'bd0e9289e2642f6a5c54faad304ce0f41e926d22', 'versionType': 'git'}], 'programFiles': ['net/sctp/associola.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.7'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.7', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.151', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.103', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.44', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.8', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/associola.c'], 'defaultStatus': 'affected'}] -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 15, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '546221b86ceeba0d8fec92d46a0604bb7b62be07', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '09e722030e8148ba4ed1e42c6b2ea57bda9f9895', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '4ba5bf7ed50f235ea4581de8e7a0002f4ed287b0', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': '6201cd1d70f1670c5b31ac506e7ab2fa7b8e7f75', 'versionType': 'git'}, {'status': 'affected', 'version': '8f840e47f190cbe61a96945c13e9551048d42cef', 'lessThan': 'bd0e9289e2642f6a5c54faad304ce0f41e926d22', 'versionType': 'git'}], 'programFiles': ['net/sctp/associola.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.7'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.7', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.151', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.103', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.44', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.8', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc6', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/associola.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport count overflow sctp_assoc_add_peer() increments the association's 16-bit transport_count for every new unique peer. Adding the 65,536th transport wraps the count to zero. SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload, then copies one sockaddr_storage for every entry in transport_addr_list. After the wrap, a diagnostic dump reserves an empty payload and writes 8 MiB of peer addresses past the skb tail. Reject a new unique peer when transport_count has reached U16_MAX. Perform the check after the existing-peer lookup so a duplicate address continues to return its existing transport at the limit. Added Reference https://git.kernel.org/stable/c/09e722030e8148ba4ed1e42c6b2ea57bda9f9895 Added Reference https://git.kernel.org/stable/c/4ba5bf7ed50f235ea4581de8e7a0002f4ed287b0 Added Reference https://git.kernel.org/stable/c/546221b86ceeba0d8fec92d46a0604bb7b62be07 Added Reference https://git.kernel.org/stable/c/6201cd1d70f1670c5b31ac506e7ab2fa7b8e7f75 Added Reference https://git.kernel.org/stable/c/bd0e9289e2642f6a5c54faad304ce0f41e926d22