← All Advisories

CVE-2026-72413

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-72413

Key Details

CVECVE-2026-72413
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

sctp: fix err_chunk memory leaks in INIT handling

When sctp_verify_init() encounters unrecognized parameters, it allocates an

err_chunk to report them. However, this chunk is leaked in several code

paths:

1. In sctp_sf_do_5_1B_init(), if security_sctp_assoc_request() fails after

sctp_verify_init() has populated err_chunk, the function returns

immediately without freeing it.

2. In sctp_sf_do_unexpected_init(), the same leak occurs on the

security_sctp_assoc_request() failure path.

3. In sctp_sf_do_unexpected_init(), on the success path after copying

unrecognized parameters to the INIT-ACK, the function returns without

freeing err_chunk, unlike sctp_sf_do_5_1B_init() which properly frees

it.

Fix all three leaks by adding sctp_chunk_free(err_chunk) calls before

returning in the error paths and on the success path in

sctp_sf_do_unexpected_init(). (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-72413
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-72413