SB20260815182 - Out-of-bounds read in Linux kernel sctp
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-74287)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in SCTP parameter processing when parsing malformed embedded address parameters in INIT or ASCONF messages. A remote attacker can send a specially crafted SCTP parameter with an embedded address length that exceeds the enclosing parameter bounds to disclose sensitive information.
The issue affects ADD_IP, DEL_IP, and SET_PRIMARY parameters that contain embedded address parameters.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/06c8bf48505f2fef265931db82d5003d302a347b
- https://git.kernel.org/stable/c/0c674b20c9cdb54f8a46c88b4d00cadf82b8f0c0
- https://git.kernel.org/stable/c/28ba1d3c956604a89168adfb4c97cfc6c509bba5
- https://git.kernel.org/stable/c/3a44b2602d57e11e2eb85958d4cd500d14a27d9e
- https://git.kernel.org/stable/c/85f54cf589163a75fa06e37d8c2a4a72824c6dd1
- https://git.kernel.org/stable/c/92e4adfee56f32a963ebb105c6cd9a1ed707262a
- https://git.kernel.org/stable/c/e9361d0ca55c4af12aac09e2572852fa91046229
- https://git.kernel.org/stable/c/ed8605c6f39b9b84f9a4631db6deb25e7f1e973c