9.1
CRITICAL CVSS 3.1
CVE-2026-53225
sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
Description

In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header; reached from the no-association lookup path, from_addr_param() then reads uninitialized bytes past the parameter. Impact: an unauthenticated SCTP peer makes the receive path read up to 16 bytes of uninitialized memory past a truncated ASCONF address parameter. The sibling __sctp_rcv_init_lookup() bounds parameters with sctp_walk_params(); this path open-codes the fetch and omits the bound. Verify the whole address parameter lies within the chunk before from_addr_param() reads it, the same class of fix as commit 51e5ad549c43 ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").

INFO

Published Date :

June 25, 2026, 9:16 a.m.

Last Modified :

July 2, 2026, 8:46 p.m.

Remotely Exploit :

Yes !

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-53225 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 CRITICAL 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
Apply kernel updates to prevent uninitialized memory reads from truncated SCTP chunks.
  • Update the Linux kernel to a patched version.
  • Ensure ASCONF parameters are properly validated.
  • Apply the fix for KMSAN uninit-value in sctp_inq_pop.
  • Verify address parameter boundaries before reading.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-53225 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-53225 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-53225 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-53225 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    Jul. 02, 2026

    Action Type Old Value New Value
    Added CWE CWE-908
    Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.176 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.143 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.210 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.36 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.94 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.13 *cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 2.6.25 up to (excluding) 5.10.259
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/446e0ecd845abc394b24ae2030a883572bec9d16 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/8ce96f1182644079249a24ac7e2ffc32e0301a46 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/8e86817b8af4d552f3c6fe04ca52bb0c8c57411d Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/928dd94db23e8ba340f83d68f7f24d831b7a4426 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/d6bd0bb7697ea8c0387b0d9d973453f479017b23 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/d796cfd06074b579d265b28401306cadd30db945 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/f76a8b323e28e0951f979dbef20a7496383c47df Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/f8373d7090b745728de66308deeecc67e8d319ce Types: Patch
  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 28, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 25, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': '446e0ecd845abc394b24ae2030a883572bec9d16', 'versionType': 'git'}, {'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': '928dd94db23e8ba340f83d68f7f24d831b7a4426', 'versionType': 'git'}, {'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': 'd796cfd06074b579d265b28401306cadd30db945', 'versionType': 'git'}, {'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': '8ce96f1182644079249a24ac7e2ffc32e0301a46', 'versionType': 'git'}, {'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': 'd6bd0bb7697ea8c0387b0d9d973453f479017b23', 'versionType': 'git'}, {'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': 'f76a8b323e28e0951f979dbef20a7496383c47df', 'versionType': 'git'}, {'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': '8e86817b8af4d552f3c6fe04ca52bb0c8c57411d', 'versionType': 'git'}, {'status': 'affected', 'version': 'df21857714398acb8b24a8bb5a6d2286dd9c59ef', 'lessThan': 'f8373d7090b745728de66308deeecc67e8d319ce', 'versionType': 'git'}], 'programFiles': ['net/sctp/input.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.25'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.25', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.259', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.210', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.176', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.143', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.94', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.36', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.13', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/input.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header; reached from the no-association lookup path, from_addr_param() then reads uninitialized bytes past the parameter. Impact: an unauthenticated SCTP peer makes the receive path read up to 16 bytes of uninitialized memory past a truncated ASCONF address parameter. The sibling __sctp_rcv_init_lookup() bounds parameters with sctp_walk_params(); this path open-codes the fetch and omits the bound. Verify the whole address parameter lies within the chunk before from_addr_param() reads it, the same class of fix as commit 51e5ad549c43 ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").
    Added Reference https://git.kernel.org/stable/c/446e0ecd845abc394b24ae2030a883572bec9d16
    Added Reference https://git.kernel.org/stable/c/8ce96f1182644079249a24ac7e2ffc32e0301a46
    Added Reference https://git.kernel.org/stable/c/8e86817b8af4d552f3c6fe04ca52bb0c8c57411d
    Added Reference https://git.kernel.org/stable/c/928dd94db23e8ba340f83d68f7f24d831b7a4426
    Added Reference https://git.kernel.org/stable/c/d6bd0bb7697ea8c0387b0d9d973453f479017b23
    Added Reference https://git.kernel.org/stable/c/d796cfd06074b579d265b28401306cadd30db945
    Added Reference https://git.kernel.org/stable/c/f76a8b323e28e0951f979dbef20a7496383c47df
    Added Reference https://git.kernel.org/stable/c/f8373d7090b745728de66308deeecc67e8d319ce
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.