CVE-2026-53004
sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks
Description
In the Linux kernel, the following vulnerability has been resolved: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks sctp_getsockopt_peer_auth_chunks() checks that the caller's optval buffer is large enough for the peer AUTH chunk list with if (len < num_chunks) return -EINVAL; but then writes num_chunks bytes to p->gauth_chunks, which lives at offset offsetof(struct sctp_authchunks, gauth_chunks) == 8 inside optval. The check is missing the sizeof(struct sctp_authchunks) = 8-byte header. When the caller supplies len == num_chunks (for any num_chunks > 0) the test passes but copy_to_user() writes sizeof(struct sctp_authchunks) = 8 bytes past the declared buffer. The sibling function sctp_getsockopt_local_auth_chunks() at the next line already has the correct check: if (len < sizeof(struct sctp_authchunks) + num_chunks) return -EINVAL; Align the peer variant with its sibling. Reproducer confirms on v7.0-13-generic: an unprivileged userspace caller that opens a loopback SCTP association with AUTH enabled, queries num_chunks with a short optval, then issues the real getsockopt with len == num_chunks and sentinel bytes painted past the buffer observes those sentinel bytes overwritten with the peer's AUTH chunk type. The bytes written are under the peer's control but land in the caller's own userspace; this is not a kernel memory corruption, but it is a kernel-side contract violation that can silently corrupt adjacent userspace data.
INFO
Published Date :
June 24, 2026, 5:17 p.m.
Last Modified :
July 14, 2026, 8:05 p.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | [email protected] |
Solution
- Update the Linux kernel to the latest version.
- Apply relevant security patches for the kernel.
- Recompile the kernel if necessary.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-53004.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-53004 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-53004
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-53004 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-53004 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Initial Analysis by [email protected]
Jul. 14, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Added CWE CWE-787 Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.141 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.91 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.33 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.10 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.175 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.209 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 2.6.24 up to (excluding) 5.10.258 Added Reference Type kernel.org: https://git.kernel.org/stable/c/0cf004ffb61cd32d140531c3a84afe975f9fc7ea Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/2b5a2c957c7769d40110f725cf23987fcef50d75 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/6849b995cda88a677bf08a05765d1db7905974fc Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/6bcf8fe4ef7967b22b814cbae9a57bbd3c853410 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/70a089cc9590aa347a61e84434116ab74619e3c3 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/a132e199de69e2a45628aa8534df1bf5d44e1b6e Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/d45c7e99caf915b0f6c716bd8ffe9d45b9685761 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/d67fbc6dea5dbf7f46c618ebf65910a276078e20 Types: Patch -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 24, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': 'a132e199de69e2a45628aa8534df1bf5d44e1b6e', 'versionType': 'git'}, {'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': '2b5a2c957c7769d40110f725cf23987fcef50d75', 'versionType': 'git'}, {'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': 'd45c7e99caf915b0f6c716bd8ffe9d45b9685761', 'versionType': 'git'}, {'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': 'd67fbc6dea5dbf7f46c618ebf65910a276078e20', 'versionType': 'git'}, {'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': '6849b995cda88a677bf08a05765d1db7905974fc', 'versionType': 'git'}, {'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': '70a089cc9590aa347a61e84434116ab74619e3c3', 'versionType': 'git'}, {'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': '6bcf8fe4ef7967b22b814cbae9a57bbd3c853410', 'versionType': 'git'}, {'status': 'affected', 'version': '65b07e5d0d09c77e98050b5f0146ead29e5add32', 'lessThan': '0cf004ffb61cd32d140531c3a84afe975f9fc7ea', 'versionType': 'git'}], 'programFiles': ['net/sctp/socket.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.24'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.24', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.258', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.209', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.175', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.141', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.91', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.33', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.10', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/socket.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks sctp_getsockopt_peer_auth_chunks() checks that the caller's optval buffer is large enough for the peer AUTH chunk list with if (len < num_chunks) return -EINVAL; but then writes num_chunks bytes to p->gauth_chunks, which lives at offset offsetof(struct sctp_authchunks, gauth_chunks) == 8 inside optval. The check is missing the sizeof(struct sctp_authchunks) = 8-byte header. When the caller supplies len == num_chunks (for any num_chunks > 0) the test passes but copy_to_user() writes sizeof(struct sctp_authchunks) = 8 bytes past the declared buffer. The sibling function sctp_getsockopt_local_auth_chunks() at the next line already has the correct check: if (len < sizeof(struct sctp_authchunks) + num_chunks) return -EINVAL; Align the peer variant with its sibling. Reproducer confirms on v7.0-13-generic: an unprivileged userspace caller that opens a loopback SCTP association with AUTH enabled, queries num_chunks with a short optval, then issues the real getsockopt with len == num_chunks and sentinel bytes painted past the buffer observes those sentinel bytes overwritten with the peer's AUTH chunk type. The bytes written are under the peer's control but land in the caller's own userspace; this is not a kernel memory corruption, but it is a kernel-side contract violation that can silently corrupt adjacent userspace data. Added Reference https://git.kernel.org/stable/c/0cf004ffb61cd32d140531c3a84afe975f9fc7ea Added Reference https://git.kernel.org/stable/c/2b5a2c957c7769d40110f725cf23987fcef50d75 Added Reference https://git.kernel.org/stable/c/6849b995cda88a677bf08a05765d1db7905974fc Added Reference https://git.kernel.org/stable/c/6bcf8fe4ef7967b22b814cbae9a57bbd3c853410 Added Reference https://git.kernel.org/stable/c/70a089cc9590aa347a61e84434116ab74619e3c3 Added Reference https://git.kernel.org/stable/c/a132e199de69e2a45628aa8534df1bf5d44e1b6e Added Reference https://git.kernel.org/stable/c/d45c7e99caf915b0f6c716bd8ffe9d45b9685761 Added Reference https://git.kernel.org/stable/c/d67fbc6dea5dbf7f46c618ebf65910a276078e20