Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-53225

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/06/2026
Última modificación:
02/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> sctp: fix uninit-value in __sctp_rcv_asconf_lookup()<br /> <br /> __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF<br /> chunk can hold the ADDIP header and a parameter header, then calls<br /> af-&gt;from_addr_param(), which reads the full address (16 bytes for IPv6)<br /> trusting the parameter&amp;#39;s declared length.<br /> <br /> An unauthenticated peer can send a truncated trailing ASCONF chunk that<br /> declares an IPv6 address parameter but stops after the 4-byte parameter<br /> header; reached from the no-association lookup path, from_addr_param() then<br /> reads uninitialized bytes past the parameter.<br /> <br /> Impact: an unauthenticated SCTP peer makes the receive path read up to 16<br /> bytes of uninitialized memory past a truncated ASCONF address parameter.<br /> <br /> The sibling __sctp_rcv_init_lookup() bounds parameters with<br /> sctp_walk_params(); this path open-codes the fetch and omits the bound.<br /> Verify the whole address parameter lies within the chunk before<br /> from_addr_param() reads it, the same class of fix as commit 51e5ad549c43<br /> ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.25 (incluyendo) 5.10.259 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (incluyendo) 5.15.210 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (incluyendo) 6.1.176 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (incluyendo) 6.6.143 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.94 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.36 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.13 (excluyendo)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*