9.1 CVE-2026-53225

Enriched by CISA Patch
 

In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header; reached from the no-association lookup path, from_addr_param() then reads uninitialized bytes past the parameter. Impact: an unauthenticated SCTP peer makes the receive path read up to 16 bytes of uninitialized memory past a truncated ASCONF address parameter. The sibling __sctp_rcv_init_lookup() bounds parameters with sctp_walk_params(); this path open-codes the fetch and omits the bound. Verify the whole address parameter lies within the chunk before from_addr_param() reads it, the same class of fix as commit 51e5ad549c43 ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").
https://nvd.nist.gov/vuln/detail/CVE-2026-53225

Categories

CWE-908 : Use of Uninitialized Resource
When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.

References


 

AFFECTED (from MITRE)


Vendor Product Versions
Linux Linux
  • df21857714398acb8b24a8bb5a6d2286dd9c59ef < 446e0ecd845abc394b24ae2030a883572bec9d16 [affected]
  • df21857714398acb8b24a8bb5a6d2286dd9c59ef < 928dd94db23e8ba340f83d68f7f24d831b7a4426 [affected]
  • df21857714398acb8b24a8bb5a6d2286dd9c59ef < d796cfd06074b579d265b28401306cadd30db945 [affected]
  • df21857714398acb8b24a8bb5a6d2286dd9c59ef < 8ce96f1182644079249a24ac7e2ffc32e0301a46 [affected]
  • df21857714398acb8b24a8bb5a6d2286dd9c59ef < d6bd0bb7697ea8c0387b0d9d973453f479017b23 [affected]
  • df21857714398acb8b24a8bb5a6d2286dd9c59ef < f76a8b323e28e0951f979dbef20a7496383c47df [affected]
  • df21857714398acb8b24a8bb5a6d2286dd9c59ef < 8e86817b8af4d552f3c6fe04ca52bb0c8c57411d [affected]
  • df21857714398acb8b24a8bb5a6d2286dd9c59ef < f8373d7090b745728de66308deeecc67e8d319ce [affected]
Linux Linux
  • 2.6.25 [affected]
  • < 2.6.25 [unaffected]
  • 5.10.259 ≤ 5.10.* [unaffected]
  • 5.15.210 ≤ 5.15.* [unaffected]
  • 6.1.176 ≤ 6.1.* [unaffected]
  • 6.6.143 ≤ 6.6.* [unaffected]
  • 6.12.94 ≤ 6.12.* [unaffected]
  • 6.18.36 ≤ 6.18.* [unaffected]
  • 7.0.13 ≤ 7.0.* [unaffected]
  • 7.1 ≤ * [unaffected]
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

CPE

cpe start end
Configuration 1
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 2.6.25 < 5.10.259
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 5.11 < 5.15.210
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 5.16 < 6.1.176
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 6.2 < 6.6.143
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 6.7 < 6.12.94
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 6.13 < 6.18.36
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* >= 6.19 < 7.0.13
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*


REMEDIATION


Patch

Url
https://git.kernel.org/stable/c/446e0ecd845abc394b24ae2030a883572bec9d16
https://git.kernel.org/stable/c/8ce96f1182644079249a24ac7e2ffc32e0301a46
https://git.kernel.org/stable/c/8e86817b8af4d552f3c6fe04ca52bb0c8c57411d
https://git.kernel.org/stable/c/928dd94db23e8ba340f83d68f7f24d831b7a4426
https://git.kernel.org/stable/c/d6bd0bb7697ea8c0387b0d9d973453f479017b23
https://git.kernel.org/stable/c/d796cfd06074b579d265b28401306cadd30db945
https://git.kernel.org/stable/c/f76a8b323e28e0951f979dbef20a7496383c47df
https://git.kernel.org/stable/c/f8373d7090b745728de66308deeecc67e8d319ce


EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry