CVE-2026-53225
sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
Description
In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header; reached from the no-association lookup path, from_addr_param() then reads uninitialized bytes past the parameter. Impact: an unauthenticated SCTP peer makes the receive path read up to 16 bytes of uninitialized memory past a truncated ASCONF address parameter. The sibling __sctp_rcv_init_lookup() bounds parameters with sctp_walk_params(); this path open-codes the fetch and omits the bound. Verify the whole address parameter lies within the chunk before from_addr_param() reads it, the same class of fix as commit 51e5ad549c43 ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").
INFO
Published Date :
June 25, 2026, 9:16 a.m.
Last Modified :
July 2, 2026, 8:46 p.m.
Remotely Exploit :
Yes !
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | CRITICAL | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Update the Linux kernel to a patched version.
- Ensure ASCONF parameters are properly validated.
- Apply the fix for KMSAN uninit-value in sctp_inq_pop.
- Verify address parameter boundaries before reading.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-53225.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-53225 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-53225
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-53225 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-53225 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Initial Analysis by [email protected]
Jul. 02, 2026
Action Type Old Value New Value Added CWE CWE-908 Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.176 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.143 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.210 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.36 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.94 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.13 *cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 2.6.25 up to (excluding) 5.10.259 Added Reference Type kernel.org: https://git.kernel.org/stable/c/446e0ecd845abc394b24ae2030a883572bec9d16 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/8ce96f1182644079249a24ac7e2ffc32e0301a46 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/8e86817b8af4d552f3c6fe04ca52bb0c8c57411d Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/928dd94db23e8ba340f83d68f7f24d831b7a4426 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/d6bd0bb7697ea8c0387b0d9d973453f479017b23 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/d796cfd06074b579d265b28401306cadd30db945 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/f76a8b323e28e0951f979dbef20a7496383c47df Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/f8373d7090b745728de66308deeecc67e8d319ce Types: Patch -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 28, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 25, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': '446e0ecd845abc394b24ae2030a883572bec9d16', 'versionType': 'git'}, {'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': '928dd94db23e8ba340f83d68f7f24d831b7a4426', 'versionType': 'git'}, {'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': 'd796cfd06074b579d265b28401306cadd30db945', 'versionType': 'git'}, {'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': '8ce96f1182644079249a24ac7e2ffc32e0301a46', 'versionType': 'git'}, {'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': 'd6bd0bb7697ea8c0387b0d9d973453f479017b23', 'versionType': 'git'}, {'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': 'f76a8b323e28e0951f979dbef20a7496383c47df', 'versionType': 'git'}, {'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': '8e86817b8af4d552f3c6fe04ca52bb0c8c57411d', 'versionType': 'git'}, {'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': 'f8373d7090b745728de66308deeecc67e8d319ce', 'versionType': 'git'}], 'programFiles': ['net/sctp/input.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.25'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.25', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.259', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.210', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.176', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.143', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.94', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.36', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.13', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/input.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header; reached from the no-association lookup path, from_addr_param() then reads uninitialized bytes past the parameter. Impact: an unauthenticated SCTP peer makes the receive path read up to 16 bytes of uninitialized memory past a truncated ASCONF address parameter. The sibling __sctp_rcv_init_lookup() bounds parameters with sctp_walk_params(); this path open-codes the fetch and omits the bound. Verify the whole address parameter lies within the chunk before from_addr_param() reads it, the same class of fix as commit 51e5ad549c43 ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop"). Added Reference https://git.kernel.org/stable/c/446e0ecd845abc394b24ae2030a883572bec9d16 Added Reference https://git.kernel.org/stable/c/8ce96f1182644079249a24ac7e2ffc32e0301a46 Added Reference https://git.kernel.org/stable/c/8e86817b8af4d552f3c6fe04ca52bb0c8c57411d Added Reference https://git.kernel.org/stable/c/928dd94db23e8ba340f83d68f7f24d831b7a4426 Added Reference https://git.kernel.org/stable/c/d6bd0bb7697ea8c0387b0d9d973453f479017b23 Added Reference https://git.kernel.org/stable/c/d796cfd06074b579d265b28401306cadd30db945 Added Reference https://git.kernel.org/stable/c/f76a8b323e28e0951f979dbef20a7496383c47df Added Reference https://git.kernel.org/stable/c/f8373d7090b745728de66308deeecc67e8d319ce