← All Advisories

CVE-2026-68161

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-68161

Key Details

CVECVE-2026-68161
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

sctp: close UDP tunnel sockets during netns teardown

proc_sctp_do_udp_port() starts per-net SCTP UDP tunneling sockets when

net.sctp.udp_port is set, and stops/restarts them when the sysctl value

changes. The netns exit path does not stop these sockets, so a namespace

can be torn down while its SCTP UDP tunnel sockets are still installed.

Close the UDP tunnel sockets from sctp_ctrlsock_exit() after unregistering

the per-net sysctl table. This prevents new sysctl writes from racing in

while the sockets are being released, and closes the sockets before the

control socket is destroyed. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-68161
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-68161