CVE-2026-74587
Linux kernel SCTP use-after-free in ASCONF handling enabling memory corruption.
Is CVE-2026-74587 being exploited?
Not confirmed. CVE-2026-74587 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.50% probability of exploitation in the next 30 days.
How severe is CVE-2026-74587?
CVE-2026-74587 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74587?
Yes. A fix has been recorded for CVE-2026-74587. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74587 affect?
CVE-2026-74587 affects Linux kernel (SCTP subsystem), Servers and network appliances with SCTP enabled, Telecom/VOIP systems using SCTP. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74587?
Apply vendor kernel updates ASAP; disable or firewall-block SCTP (IPPROTO 132) if unused.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote memory corruption via crafted SCTP ASCONF/ACK race, enabling DoS, info leak, or possible RCE/privilege escalation.
Immediate action required
- affected>= a000c01e60e40e15304ffe48fff051d17a7bea91 and < 10459b03e2d9ee12435e96f587de4d4cacdbf435
- affected>= a000c01e60e40e15304ffe48fff051d17a7bea91 and < e1bb114e09372fd6e03387ced9ef566da336ed6c
- affected>= a000c01e60e40e15304ffe48fff051d17a7bea91 and < 179676f0166230c80053a392303485b37c93dd33
- affected>= a000c01e60e40e15304ffe48fff051d17a7bea91 and < dc67d528c2fa939cec7fe3bf7f3089c8d281ca3d
- affected>= a000c01e60e40e15304ffe48fff051d17a7bea91 and < 618b5c6d049896fcfabb91afc072954c92cb2693
- affected>= a000c01e60e40e15304ffe48fff051d17a7bea91 and < 07daf4f9750104960a1d60831b2353c0d41f35fb
- affected>= a000c01e60e40e15304ffe48fff051d17a7bea91 and < d949992bc3f00027a2c755e860a11950c75f6073
- affected>= a000c01e60e40e15304ffe48fff051d17a7bea91 and < 8c283e7b56adce00193837f3311b06662466fb21
- affected3.0
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.