CVE-2026-53225
published 2026-06-25CVE-2026-53225: In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in…
PriorityP352critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.54%
41.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
__sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF
chunk can hold the ADDIP header and a parameter header, then calls
af->from_addr_param(), which reads the full address (16 bytes for IPv6)
trusting the parameter's declared length.
An unauthenticated peer can send a truncated trailing ASCONF chunk that
declares an IPv6 address parameter but stops after the 4-byte parameter
header; reached from the no-association lookup path, from_addr_param() then
reads uninitialized bytes past the parameter.
Impact: an unauthenticated SCTP peer makes the receive path read up to 16
bytes of uninitialized memory past a truncated ASCONF address parameter.
The sibling __sctp_rcv_init_lookup() bounds parameters with
sctp_walk_params(); this path open-codes the fetch and omits the bound.
Verify the whole address parameter lies within the chunk before
from_addr_param() reads it, the same class of fix as commit 51e5ad549c43
("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= df21857714398acb8b24a8bb5a6d2286dd9c59ef < 446e0ecd845abc394b24ae2030a883572bec9d16 | 446e0ecd845abc394b24ae2030a883572bec9d16 |
| linux | linux | >= df21857714398acb8b24a8bb5a6d2286dd9c59ef < 928dd94db23e8ba340f83d68f7f24d831b7a4426 | 928dd94db23e8ba340f83d68f7f24d831b7a4426 |
| linux | linux | >= df21857714398acb8b24a8bb5a6d2286dd9c59ef < d796cfd06074b579d265b28401306cadd30db945 | d796cfd06074b579d265b28401306cadd30db945 |
| linux | linux | >= df21857714398acb8b24a8bb5a6d2286dd9c59ef < 8ce96f1182644079249a24ac7e2ffc32e0301a46 | 8ce96f1182644079249a24ac7e2ffc32e0301a46 |
| linux | linux | >= df21857714398acb8b24a8bb5a6d2286dd9c59ef < d6bd0bb7697ea8c0387b0d9d973453f479017b23 | d6bd0bb7697ea8c0387b0d9d973453f479017b23 |
| linux | linux | >= df21857714398acb8b24a8bb5a6d2286dd9c59ef < f76a8b323e28e0951f979dbef20a7496383c47df | f76a8b323e28e0951f979dbef20a7496383c47df |
| linux | linux | >= df21857714398acb8b24a8bb5a6d2286dd9c59ef < 8e86817b8af4d552f3c6fe04ca52bb0c8c57411d | 8e86817b8af4d552f3c6fe04ca52bb0c8c57411d |
| linux | linux | >= df21857714398acb8b24a8bb5a6d2286dd9c59ef < f8373d7090b745728de66308deeecc67e8d319ce | f8373d7090b745728de66308deeecc67e8d319ce |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 2.6.25 < 5.10.259 | 5.10.259 |
| linux | linux_kernel | >= 5.11 < 5.15.210 | 5.15.210 |
| linux | linux_kernel | >= 5.16 < 6.1.176 | 6.1.176 |
| linux | linux_kernel | >= 6.13 < 6.18.36 | 6.18.36 |
| linux | linux_kernel | >= 6.19 < 7.0.13 | 7.0.13 |
| linux | linux_kernel | >= 6.2 < 6.6.143 | 6.6.143 |
| linux | linux_kernel | >= 6.7 < 6.12.94 | 6.12.94 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF ch
ghsa_unreviewed·2026-06-25
CVE-2026-53225 In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF ch
In the Linux kernel, the following vulnerability has been resolved:
sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
__sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF
chunk can hold the ADDIP header and a parameter header, then calls
af->from_addr_param(), which reads the full address (16 bytes for IPv6)
trusting the parameter's declared length.
An unauthenticated peer can send a truncated trailing ASCONF chunk that
declares an IPv6 address parameter but stops after the 4-byte parameter
header; reached from the no-association lookup path, from_addr_param() then
reads uninitialized bytes past the parameter.
Impact: an unauthenticated SCTP peer makes the receive path read up to 16
bytes of uninitialized memory past a truncated ASCONF address parameter.
The s
Red Hat
kernel: sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
vendor_redhat·2026-06-25·CVSS 5.5
CVE-2026-53225 [MEDIUM] CWE-130 kernel: sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
kernel: sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
A flaw was found in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted, truncated ASCONF (Address Configuration) chunk. This can cause the system to read up to 16 bytes of uninitialized memory, potentially leading to information disclosure or memory corruption.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 8) - Fix deferred
Package: kernel-rt (Red Hat Enter
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/446e0ecd845abc394b24ae2030a883572bec9d16https://git.kernel.org/stable/c/8ce96f1182644079249a24ac7e2ffc32e0301a46https://git.kernel.org/stable/c/8e86817b8af4d552f3c6fe04ca52bb0c8c57411dhttps://git.kernel.org/stable/c/928dd94db23e8ba340f83d68f7f24d831b7a4426https://git.kernel.org/stable/c/d6bd0bb7697ea8c0387b0d9d973453f479017b23https://git.kernel.org/stable/c/d796cfd06074b579d265b28401306cadd30db945https://git.kernel.org/stable/c/f76a8b323e28e0951f979dbef20a7496383c47dfhttps://git.kernel.org/stable/c/f8373d7090b745728de66308deeecc67e8d319ce
2026-06-25
Published