SB20260827121 - Out-of-bounds write in Linux kernel sctp
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-74752)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an out-of-bounds write in SCTP COOKIE_ECHO handling when processing peer-controlled cookie AUTH fields with cookie authentication disabled. A remote attacker can send a forged cookie with a crafted HMAC identifier to execute arbitrary code.
The issue is reachable when cookie authentication is disabled, and malformed AUTH parameters restored from the cookie are not validated against local backing arrays.
Remediation
Install update from vendor's website.