CVE-2026-53225

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/06/2026
Last modified:
02/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> sctp: fix uninit-value in __sctp_rcv_asconf_lookup()<br /> <br /> __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF<br /> chunk can hold the ADDIP header and a parameter header, then calls<br /> af-&gt;from_addr_param(), which reads the full address (16 bytes for IPv6)<br /> trusting the parameter&amp;#39;s declared length.<br /> <br /> An unauthenticated peer can send a truncated trailing ASCONF chunk that<br /> declares an IPv6 address parameter but stops after the 4-byte parameter<br /> header; reached from the no-association lookup path, from_addr_param() then<br /> reads uninitialized bytes past the parameter.<br /> <br /> Impact: an unauthenticated SCTP peer makes the receive path read up to 16<br /> bytes of uninitialized memory past a truncated ASCONF address parameter.<br /> <br /> The sibling __sctp_rcv_init_lookup() bounds parameters with<br /> sctp_walk_params(); this path open-codes the fetch and omits the bound.<br /> Verify the whole address parameter lies within the chunk before<br /> from_addr_param() reads it, the same class of fix as commit 51e5ad549c43<br /> ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.25 (including) 5.10.259 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.210 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.176 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.143 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.94 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.36 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.13 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*