← All Advisories

Linux Kernel SCTP ASCONF Lookup Reads Past the Validated Header Boundary, Exposing Uninitialized Memory to Downstream Address Parameter Processing

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-53225

Key Details

CVECVE-2026-53225
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-07-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsLinux Linux Kernel
Classified asCWE-908 (Use of Uninitialized Resource)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsGeneral OT
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

sctp: fix uninit-value in __sctp_rcv_asconf_lookup()

__sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF

chunk can hold the ADDIP header and a parameter header, then calls

af->from_addr_param(), which reads the full address (16 bytes for IPv6)

trusting the parameter's declared length.

An unauthenticated peer can send a truncated trailing ASCONF chunk that

declares an IPv6 address parameter but stops after the 4-byte parameter

header; reached from the no-association lookup path, from_addr_param() then

reads uninitialized bytes past the parameter.

Impact: an unauthenticated SCTP peer makes the receive path read up to 16

bytes of uninitialized memory past a truncated ASCONF address parameter.

The sibling __sctp_rcv_init_lookup() bounds parameters with

sctp_walk_params(); this path open-codes the fetch and omits the bound.

Verify the whole address parameter lies within the chunk before

from_addr_param() reads it, the same class of fix as commit 51e5ad549c43

("net: sctp: fix KMSAN uninit-value in sctp_inq_pop"). (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-53225
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-53225