7.8
HIGH CVSS 3.1
CVE-2026-53004
sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks
Description

In the Linux kernel, the following vulnerability has been resolved: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks sctp_getsockopt_peer_auth_chunks() checks that the caller's optval buffer is large enough for the peer AUTH chunk list with if (len < num_chunks) return -EINVAL; but then writes num_chunks bytes to p->gauth_chunks, which lives at offset offsetof(struct sctp_authchunks, gauth_chunks) == 8 inside optval. The check is missing the sizeof(struct sctp_authchunks) = 8-byte header. When the caller supplies len == num_chunks (for any num_chunks > 0) the test passes but copy_to_user() writes sizeof(struct sctp_authchunks) = 8 bytes past the declared buffer. The sibling function sctp_getsockopt_local_auth_chunks() at the next line already has the correct check: if (len < sizeof(struct sctp_authchunks) + num_chunks) return -EINVAL; Align the peer variant with its sibling. Reproducer confirms on v7.0-13-generic: an unprivileged userspace caller that opens a loopback SCTP association with AUTH enabled, queries num_chunks with a short optval, then issues the real getsockopt with len == num_chunks and sentinel bytes painted past the buffer observes those sentinel bytes overwritten with the peer's AUTH chunk type. The bytes written are under the peer's control but land in the caller's own userspace; this is not a kernel memory corruption, but it is a kernel-side contract violation that can silently corrupt adjacent userspace data.

INFO

Published Date :

June 24, 2026, 5:17 p.m.

Last Modified :

July 14, 2026, 8:05 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-53004 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH [email protected]
Solution
Apply kernel patches to fix an out-of-bounds write in sctp_getsockopt_peer_auth_chunks.
  • Update the Linux kernel to the latest version.
  • Apply relevant security patches for the kernel.
  • Recompile the kernel if necessary.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-53004 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-53004 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-53004 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-53004 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    Jul. 14, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-787
    Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.141 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.91 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.33 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.10 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.175 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.209 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 2.6.24 up to (excluding) 5.10.258
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/0cf004ffb61cd32d140531c3a84afe975f9fc7ea Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/2b5a2c957c7769d40110f725cf23987fcef50d75 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/6849b995cda88a677bf08a05765d1db7905974fc Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/6bcf8fe4ef7967b22b814cbae9a57bbd3c853410 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/70a089cc9590aa347a61e84434116ab74619e3c3 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/a132e199de69e2a45628aa8534df1bf5d44e1b6e Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/d45c7e99caf915b0f6c716bd8ffe9d45b9685761 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/d67fbc6dea5dbf7f46c618ebf65910a276078e20 Types: Patch
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 24, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': 'a132e199de69e2a45628aa8534df1bf5d44e1b6e', 'versionType': 'git'}, {'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': '2b5a2c957c7769d40110f725cf23987fcef50d75', 'versionType': 'git'}, {'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': 'd45c7e99caf915b0f6c716bd8ffe9d45b9685761', 'versionType': 'git'}, {'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': 'd67fbc6dea5dbf7f46c618ebf65910a276078e20', 'versionType': 'git'}, {'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': '6849b995cda88a677bf08a05765d1db7905974fc', 'versionType': 'git'}, {'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': '70a089cc9590aa347a61e84434116ab74619e3c3', 'versionType': 'git'}, {'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': '6bcf8fe4ef7967b22b814cbae9a57bbd3c853410', 'versionType': 'git'}, {'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': '0cf004ffb61cd32d140531c3a84afe975f9fc7ea', 'versionType': 'git'}], 'programFiles': ['net/sctp/socket.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.24'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.24', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.258', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.209', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.175', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.141', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.91', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.33', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.10', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/socket.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks sctp_getsockopt_peer_auth_chunks() checks that the caller's optval buffer is large enough for the peer AUTH chunk list with if (len < num_chunks) return -EINVAL; but then writes num_chunks bytes to p->gauth_chunks, which lives at offset offsetof(struct sctp_authchunks, gauth_chunks) == 8 inside optval. The check is missing the sizeof(struct sctp_authchunks) = 8-byte header. When the caller supplies len == num_chunks (for any num_chunks > 0) the test passes but copy_to_user() writes sizeof(struct sctp_authchunks) = 8 bytes past the declared buffer. The sibling function sctp_getsockopt_local_auth_chunks() at the next line already has the correct check: if (len < sizeof(struct sctp_authchunks) + num_chunks) return -EINVAL; Align the peer variant with its sibling. Reproducer confirms on v7.0-13-generic: an unprivileged userspace caller that opens a loopback SCTP association with AUTH enabled, queries num_chunks with a short optval, then issues the real getsockopt with len == num_chunks and sentinel bytes painted past the buffer observes those sentinel bytes overwritten with the peer's AUTH chunk type. The bytes written are under the peer's control but land in the caller's own userspace; this is not a kernel memory corruption, but it is a kernel-side contract violation that can silently corrupt adjacent userspace data.
    Added Reference https://git.kernel.org/stable/c/0cf004ffb61cd32d140531c3a84afe975f9fc7ea
    Added Reference https://git.kernel.org/stable/c/2b5a2c957c7769d40110f725cf23987fcef50d75
    Added Reference https://git.kernel.org/stable/c/6849b995cda88a677bf08a05765d1db7905974fc
    Added Reference https://git.kernel.org/stable/c/6bcf8fe4ef7967b22b814cbae9a57bbd3c853410
    Added Reference https://git.kernel.org/stable/c/70a089cc9590aa347a61e84434116ab74619e3c3
    Added Reference https://git.kernel.org/stable/c/a132e199de69e2a45628aa8534df1bf5d44e1b6e
    Added Reference https://git.kernel.org/stable/c/d45c7e99caf915b0f6c716bd8ffe9d45b9685761
    Added Reference https://git.kernel.org/stable/c/d67fbc6dea5dbf7f46c618ebf65910a276078e20
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.