SB2026082847 - Out-of-bounds read in Linux kernel sctp
Published: August 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-80717)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in sctp_process_param() when processing a malformed SCTP Adaptation Layer Indication parameter in an INIT chunk. A remote attacker can send a specially crafted SCTP INIT request to disclose sensitive information.
When the malformed parameter is the last parameter in the INIT chunk, four bytes from the receive-buffer tail may be copied into the state cookie returned in the INIT ACK.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/17b412468c7a44f66a385bda48cdc1e94e39bd6d
- https://git.kernel.org/stable/c/4c92c601c061e5602db2edeea54fef74aa304027
- https://git.kernel.org/stable/c/5fd7cfc708dfc988ae9920c21075e6121bc89926
- https://git.kernel.org/stable/c/74b21f52c5c5a71a05c0ff70e513f4f04ff28b17
- https://git.kernel.org/stable/c/7b7e4e3640d57bd8857f0052c8b0d8ed4e5e954a
- https://git.kernel.org/stable/c/93942b5772e0eee4147d4799cc1b936ae12fa615
- https://git.kernel.org/stable/c/bfa28cf99eb4d096c87da939f54233444d209ca5
- https://git.kernel.org/stable/c/fa7861ddbe3b525b5d541c15c3953d3569e6eb0e