CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff
In the Linux kernel, the following vulnerability has been resolved:
sctp: fix race between sctpwaitforconnect and peeloff
sctpwaitforconnect() drops and re-acquires the socket lock while waiting for the association to reach ESTABLISHED state. During this window, another thread can peeloff the association to a new socket via getsockopt(SCTPSOCKOPTPEELOFF), changing asoc->base.sk. After re-acquiring the old socket lock, sctpwaitforconnect() returns success without noticing the migration — the caller then accesses the association under the wrong lock in sctpdatamsgfromuser().
Add the same sk != asoc->base.sk check that sctpwaitforsndbuf() already has, returning an error if the association was migrated while we slept.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In sctp_wait_for_connect(), after re-acquiring the socket lock, add the same sk != asoc->base.sk check used by sctp_wait_for_sndbuf(); return an error if the association was migrated via getsockopt(SCTP_SOCKOPT_PEELOFF).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63971?
The severity of CVE-2026-63971 is rated at 37.
What systems are affected by CVE-2026-63971?
CVE-2026-63971 affects the Linux kernel.
How do I fix CVE-2026-63971?
To fix CVE-2026-63971, it is recommended to update to the latest version of the Linux kernel that addresses this vulnerability.
What type of vulnerability is CVE-2026-63971?
CVE-2026-63971 is a race condition vulnerability in the SCTP implementation of the Linux kernel.
Can CVE-2026-63971 affect system stability?
Yes, CVE-2026-63971 can potentially affect system stability due to the race condition between sctp_wait_for_connect and peeloff.