SB20260827121 - Out-of-bounds write in Linux kernel sctp



SB20260827121 - Out-of-bounds write in Linux kernel sctp

Published: August 27, 2026

Security Bulletin ID SB20260827121
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Out-of-bounds write (CVE-ID: CVE-2026-74752)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in SCTP COOKIE_ECHO handling when processing peer-controlled cookie AUTH fields with cookie authentication disabled. A remote attacker can send a forged cookie with a crafted HMAC identifier to execute arbitrary code.

The issue is reachable when cookie authentication is disabled, and malformed AUTH parameters restored from the cookie are not validated against local backing arrays.


Remediation

Install update from vendor's website.