Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74469

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
15/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> sctp: prevent peer transport count overflow<br /> <br /> sctp_assoc_add_peer() increments the association&amp;#39;s 16-bit transport_count<br /> for every new unique peer. Adding the 65,536th transport wraps the count to<br /> zero.<br /> <br /> SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,<br /> then copies one sockaddr_storage for every entry in transport_addr_list.<br /> After the wrap, a diagnostic dump reserves an empty payload and writes<br /> 8 MiB of peer addresses past the skb tail.<br /> <br /> Reject a new unique peer when transport_count has reached U16_MAX. Perform<br /> the check after the existing-peer lookup so a duplicate address continues<br /> to return its existing transport at the limit.

Impacto