๐Ÿ” CVE Alert

CVE-2026-53225

UNKNOWN 0.0

sctp: fix uninit-value in __sctp_rcv_asconf_lookup()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header; reached from the no-association lookup path, from_addr_param() then reads uninitialized bytes past the parameter. Impact: an unauthenticated SCTP peer makes the receive path read up to 16 bytes of uninitialized memory past a truncated ASCONF address parameter. The sibling __sctp_rcv_init_lookup() bounds parameters with sctp_walk_params(); this path open-codes the fetch and omits the bound. Verify the whole address parameter lies within the chunk before from_addr_param() reads it, the same class of fix as commit 51e5ad549c43 ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jun 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
df21857714398acb8b24a8bb5a6d2286dd9c59ef < 446e0ecd845abc394b24ae2030a883572bec9d16 df21857714398acb8b24a8bb5a6d2286dd9c59ef < 928dd94db23e8ba340f83d68f7f24d831b7a4426 df21857714398acb8b24a8bb5a6d2286dd9c59ef < d796cfd06074b579d265b28401306cadd30db945 df21857714398acb8b24a8bb5a6d2286dd9c59ef < 8ce96f1182644079249a24ac7e2ffc32e0301a46 df21857714398acb8b24a8bb5a6d2286dd9c59ef < d6bd0bb7697ea8c0387b0d9d973453f479017b23 df21857714398acb8b24a8bb5a6d2286dd9c59ef < f76a8b323e28e0951f979dbef20a7496383c47df df21857714398acb8b24a8bb5a6d2286dd9c59ef < 8e86817b8af4d552f3c6fe04ca52bb0c8c57411d df21857714398acb8b24a8bb5a6d2286dd9c59ef < f8373d7090b745728de66308deeecc67e8d319ce
Linux / Linux
2.6.25

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/446e0ecd845abc394b24ae2030a883572bec9d16 git.kernel.org: https://git.kernel.org/stable/c/928dd94db23e8ba340f83d68f7f24d831b7a4426 git.kernel.org: https://git.kernel.org/stable/c/d796cfd06074b579d265b28401306cadd30db945 git.kernel.org: https://git.kernel.org/stable/c/8ce96f1182644079249a24ac7e2ffc32e0301a46 git.kernel.org: https://git.kernel.org/stable/c/d6bd0bb7697ea8c0387b0d9d973453f479017b23 git.kernel.org: https://git.kernel.org/stable/c/f76a8b323e28e0951f979dbef20a7496383c47df git.kernel.org: https://git.kernel.org/stable/c/8e86817b8af4d552f3c6fe04ca52bb0c8c57411d git.kernel.org: https://git.kernel.org/stable/c/f8373d7090b745728de66308deeecc67e8d319ce