Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3444 articles · 168093 vulns · 36/41 feeds (7d)
← Back to list
9.1
CVE-2026-53225EXPLOITEDPATCHED
linux · linux kernel

sctp: fix uninit-value in __sctp_rcv_asconf_lookup()

Description

In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header; reached from the no-association lookup path, from_addr_param() then reads uninitialized bytes past the parameter. Impact: an unauthenticated SCTP peer makes the receive path read up to 16 bytes of uninitialized memory past a truncated ASCONF address parameter. The sibling __sctp_rcv_init_lookup() bounds parameters with sctp_walk_params(); this path open-codes the fetch and omits the bound. Verify the whole address parameter lies within the chunk before from_addr_param() reads it, the same class of fix as commit 51e5ad549c43 ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").

Affected Products

VendorProductVersions
linuxlinux kerneldf21857714398acb8b24a8bb5a6d2286dd9c59ef, df21857714398acb8b24a8bb5a6d2286dd9c59ef, df21857714398acb8b24a8bb5a6d2286dd9c59ef, df21857714398acb8b24a8bb5a6d2286dd9c59ef, df21857714398acb8b24a8bb5a6d2286dd9c59ef, df21857714398acb8b24a8bb5a6d2286dd9c59ef, df21857714398acb8b24a8bb5a6d2286dd9c59ef, df21857714398acb8b24a8bb5a6d2286dd9c59ef, 2.6.25

References

  • https://git.kernel.org/stable/c/446e0ecd845abc394b24ae2030a883572bec9d16
  • https://git.kernel.org/stable/c/928dd94db23e8ba340f83d68f7f24d831b7a4426
  • https://git.kernel.org/stable/c/d796cfd06074b579d265b28401306cadd30db945
  • https://git.kernel.org/stable/c/8ce96f1182644079249a24ac7e2ffc32e0301a46
  • https://git.kernel.org/stable/c/d6bd0bb7697ea8c0387b0d9d973453f479017b23
  • https://git.kernel.org/stable/c/f76a8b323e28e0951f979dbef20a7496383c47df
  • https://git.kernel.org/stable/c/8e86817b8af4d552f3c6fe04ca52bb0c8c57411d
  • https://git.kernel.org/stable/c/f8373d7090b745728de66308deeecc67e8d319ce

Related News (3 articles)

Tier A
Microsoft MSRC1h ago
CVE-2026-53225 sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-53225 | Linux Kernel up to 7.0.12 sctp net/sctp/input.c __sctp_rcv_asconf_lookup header uninitialized pointer
→ No new info (linked only)
Tier C
Linux Kernel CVEs3d ago
CVE-2026-53225: sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
446e0ecd845abc394b24ae2030a883572bec9d16928dd94db23e8ba340f83d68f7f24d831b7a4426d796cfd06074b579d265b28401306cadd30db9458ce96f1182644079249a24ac7e2ffc32e0301a46d6bd0bb7697ea8c0387b0d9d973453f479017b23f76a8b323e28e0951f979dbef20a7496383c47df8e86817b8af4d552f3c6fe04ca52bb0c8c57411df8373d7090b745728de66308deeecc67e8d319ce05.10.2595.15.2106.1.1766.6.1436.12.946.18.367.0.137.1
PublishedJun 25, 2026
Last enriched2d agov3
Trending Score65
Source articles3
Independent3
Info Completeness8/14
Missing: cvss, epss, cwe, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-31431EXPKEV
crypto: algif_aead - Revert to operating out-of-place
Trending: 111
HIGHCVE-2026-43284EXPKEV
xfrm: esp: avoid in-place decrypt on shared skb frags
Trending: 106
HIGHCVE-2026-43500EXPKEV
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
Trending: 100
HIGHCVE-2026-46243EXP
smb: client: reject userspace cifs.spnego descriptions
Trending: 86
HIGHCVE-2026-46333EXP
ptrace: slightly saner 'get_dumpable()' logic
Trending: 70

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 25, 2026
Discovered by ZDM
Jun 25, 2026
Updated: description, severity, affectedVersions
Jun 25, 2026
Updated: description, affectedVersions, exploitAvailable, activelyExploited
Jun 25, 2026
Actively Exploited
Jun 28, 2026
Exploit Available
Jun 28, 2026
Patch Available
Jun 28, 2026

Version History

v3
Last enriched 2d ago
v3Tier C2d ago

Updated description with detailed technical information, added new affected versions, and marked exploit availability and active exploitation status as true.

descriptionaffectedVersionsexploitAvailableactivelyExploited
via Linux Kernel CVEs
v2Tier C3d ago

Updated severity to CRITICAL, added affected version 7.0.12, and corrected exploit availability to false.

descriptionseverityaffectedVersions
via VulDB
v13d ago

Initial creation