LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-53225

linux · linux kernel

Published
CVSS9.1
Severitycritical
WeaknessCWE-908
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Description

In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header; reached from the no-association lookup path, from_addr_param() then reads uninitialized bytes past the parameter. Impact: an unauthenticated SCTP peer makes the receiv

References

← Back to the CVE Tracker

Our coverage of CVE-2026-53225

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-53225.