cbcvebase.
CVE-2026-53225
published 2026-06-25

CVE-2026-53225: In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in…

PriorityP352critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.54%
41.9th percentile
In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header; reached from the no-association lookup path, from_addr_param() then reads uninitialized bytes past the parameter. Impact: an unauthenticated SCTP peer makes the receive path read up to 16 bytes of uninitialized memory past a truncated ASCONF address parameter. The sibling __sctp_rcv_init_lookup() bounds parameters with sctp_walk_params(); this path open-codes the fetch and omits the bound. Verify the whole address parameter lies within the chunk before from_addr_param() reads it, the same class of fix as commit 51e5ad549c43 ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").

Affected

24 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= df21857714398acb8b24a8bb5a6d2286dd9c59ef < 446e0ecd845abc394b24ae2030a883572bec9d16446e0ecd845abc394b24ae2030a883572bec9d16
linuxlinux>= df21857714398acb8b24a8bb5a6d2286dd9c59ef < 928dd94db23e8ba340f83d68f7f24d831b7a4426928dd94db23e8ba340f83d68f7f24d831b7a4426
linuxlinux>= df21857714398acb8b24a8bb5a6d2286dd9c59ef < d796cfd06074b579d265b28401306cadd30db945d796cfd06074b579d265b28401306cadd30db945
linuxlinux>= df21857714398acb8b24a8bb5a6d2286dd9c59ef < 8ce96f1182644079249a24ac7e2ffc32e0301a468ce96f1182644079249a24ac7e2ffc32e0301a46
linuxlinux>= df21857714398acb8b24a8bb5a6d2286dd9c59ef < d6bd0bb7697ea8c0387b0d9d973453f479017b23d6bd0bb7697ea8c0387b0d9d973453f479017b23
linuxlinux>= df21857714398acb8b24a8bb5a6d2286dd9c59ef < f76a8b323e28e0951f979dbef20a7496383c47dff76a8b323e28e0951f979dbef20a7496383c47df
linuxlinux>= df21857714398acb8b24a8bb5a6d2286dd9c59ef < 8e86817b8af4d552f3c6fe04ca52bb0c8c57411d8e86817b8af4d552f3c6fe04ca52bb0c8c57411d
linuxlinux>= df21857714398acb8b24a8bb5a6d2286dd9c59ef < f8373d7090b745728de66308deeecc67e8d319cef8373d7090b745728de66308deeecc67e8d319ce
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 2.6.25 < 5.10.2595.10.259
linuxlinux_kernel>= 5.11 < 5.15.2105.15.210
linuxlinux_kernel>= 5.16 < 6.1.1766.1.176
linuxlinux_kernel>= 6.13 < 6.18.366.18.36
linuxlinux_kernel>= 6.19 < 7.0.137.0.13
linuxlinux_kernel>= 6.2 < 6.6.1436.6.143
linuxlinux_kernel>= 6.7 < 6.12.946.12.94

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.