Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-52924

9.8 · CRITICAL
Published Jun 24, 2026 linux CWE-416

Overview

CVE-2026-52924 is a critical-severity vulnerability affecting linux linux_kernel. It was published on June 24, 2026 and has a CVSS 3.1 base score of 9.8 (CRITICAL).

This vulnerability has a CVSS 3.1 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

sctp: purge outqueue on stale COOKIE-ECHO handling

sctp_stream_update() is only invoked when the association is moved into

COOKIE_WAIT during association setup/reconfiguration. In this path, the

outbound stream scheduler state (stream->out_curr) is expected to be

clean, since no user data should have been transmitted yet unless the

state machine has already partially progressed.

However, a corner case exists in sctp_sf_do_5_2_6_stale(): when a

Stale Cookie ERROR is received, the association is rolled back from

COOKIE_ECHOED to COOKIE_WAIT. In this scenario, user data may already

have been queued and even bundled with the COOKIE-ECHO chunk.

During the rollback, sctp_stream_update() frees the old stream table

and installs a new one, but it does not invalidate stream->out_curr.

As a result, out_curr may still point to a freed sctp_stream_out

entry from the previous stream state.

Later, SCTP scheduler dequeue paths (F

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 4.15, < 5.10.259 Affected

Frequently Asked Questions

What is CVE-2026-52924?

CVE-2026-52924 is a critical-severity vulnerability affecting linux linux_kernel. It was published on June 24, 2026 and has a CVSS 3.1 base score of 9.8 (CRITICAL).

How severe is CVE-2026-52924?

This vulnerability has a CVSS 3.1 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2026-52924?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-52924?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-52924 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.