Sploitus

CVE-2026-72242

No indexed exploits for CVE-2026-72242 yet

In the Linux kernel, the following vulnerability has been resolved: selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() selinux_sctp_bind_connect() dereferences sk->sk_socket to pass a struct socket * to selinux_socket_bind() and selinux_socket_connect_helper(). However, when the hook is invoked from the ASCONF softirq path (sctp_process_asconf), there is no file reference guaranteeing that sk->sk_socket is non-NULL. The setsockopt callers (bindx, connectx, set_primary, sendmsg connect) hold a file reference and are not affected. Both selinux_socket_bind() and selinux_socket_connect_helper() immediately resolve sock->sk, never using the struct socket * for anything else. Refactor the inner logic into helpers that take a struct sock * directly so that selinux_sctp_bind_connect() never needs to touch sk->sk_socket at all.

CVSS 3.1
7.5 HIGH
EPSS
0.7% (50th percentile)
NVD status
Received
Published
2026-08-15
CVE-2026-72242 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-72242 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-72242 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.