cbcvebase.
CVE-2026-53246
published 2026-06-25

CVE-2026-53246: In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing When a listening…

PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.44%
36.2th percentile
In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing When a listening SCTP server processes a COOKIE_ECHO chunk, the cached peer INIT chunk embedded after the cookie is parsed and its parameters are later walked by sctp_process_init() using sctp_walk_params(). However, the chunk header length of this cached INIT chunk was not validated against the remaining buffer in the COOKIE_ECHO payload. If the length field is inflated, the parameter walk can run beyond the actual received data, leading to out-of-bounds reads and potential memory corruption during later parameter handling (e.g. STATE_COOKIE processing and kmemdup() copies). Add a bounds check in sctp_unpack_cookie() to ensure the cached INIT chunk length does not exceed the available data in the COOKIE_ECHO buffer before it is used.

Affected

18 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cc272185c9a9a4b7febc2de52eeaa3d00f19091ecc272185c9a9a4b7febc2de52eeaa3d00f19091e
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < edccbf3d63b0a3362bc916ea72edacc1e1ca456aedccbf3d63b0a3362bc916ea72edacc1e1ca456a
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0861615c28de668669d748ef4eb913ea9262d13b0861615c28de668669d748ef4eb913ea9262d13b
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 2.6.12.1 < 6.18.366.18.36
linuxlinux_kernel>= 6.19 < 7.0.137.0.13

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.