CVE-2026-53225 Details
Description
In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header; reached from the no-association lookup path, from_addr_param() then reads uninitialized bytes past the parameter. Impact: an unauthenticated SCTP peer makes the receive path read up to 16 bytes of uninitialized memory past a truncated ASCONF address parameter. The sibling __sctp_rcv_init_lookup() bounds parameters with sctp_walk_params(); this path open-codes the fetch and omits the bound. Verify the whole address parameter lies within the chunk before from_addr_param() reads it, the same class of fix as commit 51e5ad549c43 ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").
A vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation allows an unauthenticated peer to cause the kernel to read uninitialized memory. This issue arises in the __sctp_rcv_asconf_lookup() function, which improperly validates ASCONF chunks before processing them. Specifically, the function trusts the declared length of IPv6 address parameters, leading to the potential for reading up to 16 bytes of uninitialized memory. The vulnerability can be exploited by sending a truncated ASCONF chunk that declares an IPv6 address but omits part of the data, taking advantage of the no-association lookup path.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for upgrading the kernel can be found in the official Linux kernel documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/446e0ecd845abc394b24ae2030a883572bec9d16 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8ce96f1182644079249a24ac7e2ffc32e0301a46 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8e86817b8af4d552f3c6fe04ca52bb0c8c57411d | kernel.org | Patch |
| https://git.kernel.org/stable/c/928dd94db23e8ba340f83d68f7f24d831b7a4426 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d6bd0bb7697ea8c0387b0d9d973453f479017b23 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d796cfd06074b579d265b28401306cadd30db945 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f76a8b323e28e0951f979dbef20a7496383c47df | kernel.org | Patch |
| https://git.kernel.org/stable/c/f8373d7090b745728de66308deeecc67e8d319ce | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-908 | Use of Uninitialized Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.25, < 5.10.259 >= 5.11, < 5.15.210 >= 5.16, < 6.1.176 >= 6.2, < 6.6.143 >= 6.7, < 6.12.94 >= 6.13, < 6.18.36 >= 6.19, < 7.0.13 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 7.1 rc5 7.1 rc6 7.1 rc7 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jun 28, 2026 | CVE Modified | kernel.org |
| Jun 25, 2026 | New CVE Received | kernel.org |