Answer in brief
CVE-2026-68162 records a Unknown severity vulnerability in sctp: avoid auth_enable sysctl UAF during netns teardown. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=10c869a52f266e40f548cc3c565d14930a5edafc <19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4 || >=7ec30c54f339c640aa7e49d7e9f7bbed6bd42bf6 <66700c0719675e0e118ae83b2d7168dacd69dd3d || >=c184bc621e3cef03ac9ba81a50dda2dae6a21d36 <626bda8cfe43dff19a9833ff6ba055a817b5455c || >=15649fd5415eda664ef35780c2013adeb5d9c695 <be6aae9d1b91c603adb35872d37d40e83daf8758 || >=15649fd5415eda664ef35780c2013adeb5d9c695 <a50e73488e0bbdd262b3be3c9a1d8dd078382381 || >=15649fd5415eda664ef35780c2013adeb5d9c695 <f8d5e7846025f4ab15a461235f8ebae9094a361a || dc583e7e5f8515ca489c0df28e4362a70eade382 || bd2a2939423566c654545fa3e96a656662a0af9e || 1b67030d39f2b00f94ac1f0af11ba6657589e4d3 || >=5.4.290 <5.4.292 || >=6.6.72 <6.6.151 || >=6.12.10 <6.12.101 || >=5.10.234 <5.11 || >=5.15.177 <5.16 || >=6.1.125 <6.2 | 19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4, 66700c0719675e0e118ae83b2d7168dacd69dd3d, 626bda8cfe43dff19a9833ff6ba055a817b5455c, be6aae9d1b91c603adb35872d37d40e83daf8758, a50e73488e0bbdd262b3be3c9a1d8dd078382381, f8d5e7846025f4ab15a461235f8ebae9094a361a, 5.4.292, 6.6.151, 6.12.101, 5.11, 5.16, 6.2 |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns teardown proc_sctp_do_auth() updates the SCTP control socket after changing net.sctp.auth_enable. The handler gets the per-net SCTP state from ctl->data, so an already opened sysctl file can still target a network namespace while that namespace is being torn down. SCTP previously registered its per-net sysctls from sctp_defaults_init(), while the control socket is created later from sctp_ctrlsock_init(). This exposed a window during initialization where auth_enable was writable before net->sctp.ctl_sock existed, and a teardown window where auth_enable stayed writable after inet_ctl_sock_destroy() had released the control socket. Move the per-net SCTP sysctl registration into sctp_ctrlsock_init() after sctp_ctl_sock_init() succeeds, and unregister the sysctl table before destroying the control socket in sctp_ctrlsock_exit(). If sysctl registration fails after the control socket was created, destroy the control socket in the same init path. Make sctp_sysctl_net_unregister() tolerate a missing header and clear the saved pointer so init-error and exit paths can safely share the unregister helper.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68162 records a Unknown severity vulnerability in sctp: avoid auth_enable sysctl UAF during netns teardown. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=10c869a52f266e40f548cc3c565d14930a5edafc <19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4 || >=7ec30c54f339c640aa7e49d7e9f7bbed6bd42bf6 <66700c0719675e0e118ae83b2d7168dacd69dd3d || >=c184bc621e3cef03ac9ba81a50dda2dae6a21d36 <626bda8cfe43dff19a9833ff6ba055a817b5455c || >=15649fd5415eda664ef35780c2013adeb5d9c695 <be6aae9d1b91c603adb35872d37d40e83daf8758 || >=15649fd5415eda664ef35780c2013adeb5d9c695 <a50e73488e0bbdd262b3be3c9a1d8dd078382381 || >=15649fd5415eda664ef35780c2013adeb5d9c695 <f8d5e7846025f4ab15a461235f8ebae9094a361a || dc583e7e5f8515ca489c0df28e4362a70eade382 || bd2a2939423566c654545fa3e96a656662a0af9e || 1b67030d39f2b00f94ac1f0af11ba6657589e4d3 || >=5.4.290 <5.4.292 || >=6.6.72 <6.6.151 || >=6.12.10 <6.12.101 || >=5.10.234 <5.11 || >=5.15.177 <5.16 || >=6.1.125 <6.2 | 19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4, 66700c0719675e0e118ae83b2d7168dacd69dd3d, 626bda8cfe43dff19a9833ff6ba055a817b5455c, be6aae9d1b91c603adb35872d37d40e83daf8758, a50e73488e0bbdd262b3be3c9a1d8dd078382381, f8d5e7846025f4ab15a461235f8ebae9094a361a, 5.4.292, 6.6.151, 6.12.101, 5.11, 5.16, 6.2 |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns teardown proc_sctp_do_auth() updates the SCTP control socket after changing net.sctp.auth_enable. The handler gets the per-net SCTP state from ctl->data, so an already opened sysctl file can still target a network namespace while that namespace is being torn down. SCTP previously registered its per-net sysctls from sctp_defaults_init(), while the control socket is created later from sctp_ctrlsock_init(). This exposed a window during initialization where auth_enable was writable before net->sctp.ctl_sock existed, and a teardown window where auth_enable stayed writable after inet_ctl_sock_destroy() had released the control socket. Move the per-net SCTP sysctl registration into sctp_ctrlsock_init() after sctp_ctl_sock_init() succeeds, and unregister the sysctl table before destroying the control socket in sctp_ctrlsock_exit(). If sysctl registration fails after the control socket was created, destroy the control socket in the same init path. Make sctp_sysctl_net_unregister() tolerate a missing header and clear the saved pointer so init-error and exit paths can safely share the unregister helper.
Quoted source text, attributed separately from HOL analysis.