Back to overview

CVE-2026-53225

Description
In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header; reached from the no-association lookup path, from_addr_param() then reads uninitialized bytes past the parameter. Impact: an unauthenticated SCTP peer makes the receive path read up to 16 bytes of uninitialized memory past a truncated ASCONF address parameter. The sibling __sctp_rcv_init_lookup() bounds parameters with sctp_walk_params(); this path open-codes the fetch and omits the bound. Verify the whole address parameter lies within the chunk before from_addr_param() reads it, the same class of fix as commit 51e5ad549c43 ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").

Metadata

CVE ID
CVE-2026-53225
State
PUBLISHED
Assigner
Linux
Reserved
2026-06-09 07:44 UTC
Published
2026-06-25 08:39 UTC
Last updated
2026-06-25 08:39 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux df21857714398acb8b24a8bb5a6d2286dd9c59ef < 446e0ecd845abc394b24ae2030a883572bec9d16, df21857714398acb8b24a8bb5a6d2286dd9c59ef < 928dd94db23e8ba340f83d68f7f24d831b7a4426, df21857714398acb8b24a8bb5a6d2286dd9c59ef < d796cfd06074b579d265b28401306cadd30db945, df21857714398acb8b24a8bb5a6d2286dd9c59ef < 8ce96f1182644079249a24ac7e2ffc32e0301a46 …
Linux Linux 2.6.25, 0 < 2.6.25, 5.10.259 ≤ 5.10.*, 5.15.210 ≤ 5.15.* …
Back to overview