CVE-2026-15422 Details
Description
The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs during packet classification (i.e. before SCTP integrity checks or IPsec policy are applied) a remote, unauthenticated attacker can send a crafted SCTP INIT ACK packet with malformed address parameters to cause an out-of-bounds access and kernel heap corruption, which may lead to remote code execution. The flaw has existed since 2010 (illumos-gate commit a5407c02), and affects any illumos distribution prior to illumos-gate commit 53a3efde.
A vulnerability exists in the Illumos operating system's Stream Control Transmission Protocol (SCTP) implementation, specifically in how it processes INIT ACK chunks. The issue arises because the association lookup for these chunks does not properly validate the address parameters before applying SCTP integrity checks or IPsec policies. This oversight allows a remote, unauthenticated attacker to send a crafted SCTP INIT ACK packet with malformed address parameters, causing out-of-bounds access and corruption of the kernel heap. Such heap corruption can potentially be exploited to execute arbitrary code. This vulnerability has been present since 2010 and affects all Illumos distributions prior to the latest commit that addresses this issue.
Users can apply the available patch from the Illumos Security Team. After applying the patch, the hotpatch mentioned in the CVE description can be used to temporarily mitigate the vulnerability on a running system.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 16, 2026CISA-ADP
Assessed Jul 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/illumos/illumos-gate/commit/53a3efdeff8e6745bbfb69c5360f94962fb79e75 | illumos | Source CodeVendor |
| https://illumos.org/issues/18117 | illumos | Issue TrackingTechnical DescriptionVendor |
| https://illumos.topicbox.com/groups/developer/Ta1a8e2e1f7f928df/18117-sctp-needs-to-better-check-init-ack-chunk-parameters | illumos | Issue TrackingMailing ListRemedyTechnical DescriptionVendor |
Weakness Enumeration
Affected Products
| Product | Versions |
|---|---|
| illumos | < 53a3efde |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 17, 2026 | CVE Modified | CISA-ADP |
| Jul 16, 2026 | New CVE Received | illumos |
Volerion