← All Advisories

CVE-2026-63971

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-63971

Key Details

CVECVE-2026-63971
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux Kernel and Linux Linux
Classified asCWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
LinuxLinux
SubsystemsGeneral OT
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

sctp: fix race between sctp_wait_for_connect and peeloff

sctp_wait_for_connect() drops and re-acquires the socket lock while

waiting for the association to reach ESTABLISHED state. During this

window, another thread can peeloff the association to a new socket via

getsockopt(SCTP_SOCKOPT_PEELOFF), changing asoc->base.sk. After

re-acquiring the old socket lock, sctp_wait_for_connect() returns

success without noticing the migration — the caller then accesses

the association under the wrong lock in sctp_datamsg_from_user().

Add the same sk != asoc->base.sk check that sctp_wait_for_sndbuf()

already has, returning an error if the association was migrated while

we slept. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-63971
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-63971