SB20260827122 - Out-of-bounds read in Linux kernel sctp



SB20260827122 - Out-of-bounds read in Linux kernel sctp

Published: August 27, 2026

Security Bulletin ID SB20260827122
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Out-of-bounds read (CVE-ID: CVE-2026-74752)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in SCTP COOKIE_ECHO handling when processing peer-controlled cookie AUTH fields with cookie authentication disabled. A remote attacker can send a forged cookie with a crafted RANDOM length to disclose sensitive information.

The issue is reachable when cookie authentication is disabled, and malformed AUTH parameters restored from the cookie are not validated against local backing arrays.


Remediation

Install update from vendor's website.