cbcvebase.
CVE-2026-53004
published 2026-06-24

CVE-2026-53004: In the Linux kernel, the following vulnerability has been resolved: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
3.0th percentile
In the Linux kernel, the following vulnerability has been resolved: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks sctp_getsockopt_peer_auth_chunks() checks that the caller's optval buffer is large enough for the peer AUTH chunk list with if (len gauth_chunks, which lives at offset offsetof(struct sctp_authchunks, gauth_chunks) == 8 inside optval. The check is missing the sizeof(struct sctp_authchunks) = 8-byte header. When the caller supplies len == num_chunks (for any num_chunks > 0) the test passes but copy_to_user() writes sizeof(struct sctp_authchunks) = 8 bytes past the declared buffer. The sibling function sctp_getsockopt_local_auth_chunks() at the next line already has the correct check: if (len < sizeof(struct sctp_authchunks) + num_chunks) return -EINVAL; Align the peer variant with its sibling. Reproducer confirms on v7.0-13-generic: an unprivileged userspace caller that opens a loopback SCTP association with AUTH enabled, queries num_chunks with a short optval, then issues the real getsockopt with len == num_chunks and sentinel bytes painted past the buffer observes those sentinel bytes overwritten with the peer's AUTH chunk type. The bytes written are under the peer's control but land in the caller's own userspace; this is not a kernel memory corruption, but it is a kernel-side contract violation that can silently corrupt adjacent userspace data.

Affected

56 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 65b07e5d0d09c77e98050b5f0146ead29e5add32 < a132e199de69e2a45628aa8534df1bf5d44e1b6ea132e199de69e2a45628aa8534df1bf5d44e1b6e
linuxlinux>= 65b07e5d0d09c77e98050b5f0146ead29e5add32 < 2b5a2c957c7769d40110f725cf23987fcef50d752b5a2c957c7769d40110f725cf23987fcef50d75
linuxlinux>= 65b07e5d0d09c77e98050b5f0146ead29e5add32 < d45c7e99caf915b0f6c716bd8ffe9d45b9685761d45c7e99caf915b0f6c716bd8ffe9d45b9685761
linuxlinux>= 65b07e5d0d09c77e98050b5f0146ead29e5add32 < d67fbc6dea5dbf7f46c618ebf65910a276078e20d67fbc6dea5dbf7f46c618ebf65910a276078e20
linuxlinux>= 65b07e5d0d09c77e98050b5f0146ead29e5add32 < 6849b995cda88a677bf08a05765d1db7905974fc6849b995cda88a677bf08a05765d1db7905974fc
linuxlinux>= 65b07e5d0d09c77e98050b5f0146ead29e5add32 < 70a089cc9590aa347a61e84434116ab74619e3c370a089cc9590aa347a61e84434116ab74619e3c3
linuxlinux>= 65b07e5d0d09c77e98050b5f0146ead29e5add32 < 6bcf8fe4ef7967b22b814cbae9a57bbd3c8534106bcf8fe4ef7967b22b814cbae9a57bbd3c853410
linuxlinux>= 65b07e5d0d09c77e98050b5f0146ead29e5add32 < 0cf004ffb61cd32d140531c3a84afe975f9fc7ea0cf004ffb61cd32d140531c3a84afe975f9fc7ea
linuxlinux_kernel
linuxlinux_kernel>= 2.6.24 < 5.10.2585.10.258
linuxlinux_kernel>= 5.11 < 5.15.2095.15.209
linuxlinux_kernel>= 5.16 < 6.1.1756.1.175
linuxlinux_kernel>= 6.13 < 6.18.336.18.33
linuxlinux_kernel>= 6.19 < 7.0.107.0.10
linuxlinux_kernel>= 6.2 < 6.6.1416.6.141
linuxlinux_kernel>= 6.7 < 6.12.916.12.91
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15
ubuntulinux-azure-6.8
ubuntulinux-azure-fde

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu7.1HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.