VDB

CVE-2026-89476

CVE-2026-89476 PUBLISHED CVSS 7.5 HIGH

Reported by Linux · Published September 11, 2026

In the Linux kernel, the following vulnerability has been resolved: sctp: fix stream->outcnt underflow on duplicate RECONF responses A cached RECONF chunk may contain more than one request parameter. A duplicate response can therefore find and process the same ADD_OUT request again while another parameter is still outstanding, rolling back outcnt twice and possibly underflowing it. Track outstanding request types as bits and clear each bit after its first response. Later responses for the same request are then ignored.

EPSS 0.69% · 51.2th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.69%
51.2th percentile

Affected Products

VendorProductVersions
LinuxLinux11ae76e67a179f25ae8f772d62a7ddf717b1cdf3, 11ae76e67a179f25ae8f772d62a7ddf717b1cdf3, 11ae76e67a179f25ae8f772d62a7ddf717b1cdf3
LinuxLinux4.12, 0, 5.10.270
LinuxLinux7.3-rc1, 11ae76e67a179f25ae8f772d62a7ddf717b1cdf3, 11ae76e67a179f25ae8f772d62a7ddf717b1cdf3
linuxlinux_kernel4.12, 4.12, 4.12

Timeline

  • Sep 11, 2026 CVE Published
  • Sep 12, 2026 EPSS Score
  • Sep 12, 2026 Coalition ESS Score
  • Sep 13, 2026 EPSS Score
  • Sep 14, 2026 CVE Updated
  • Sep 15, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›