Out-of-bounds read in Linux kernel - CVE-2026-53225
Published: June 26, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in __sctp_rcv_asconf_lookup() in net/sctp/input.c when processing a truncated trailing ASCONF chunk containing a declared IPv6 address parameter. A remote attacker can send a specially crafted SCTP packet to disclose sensitive information.
The issue is reachable from the no-association lookup path.
How to mitigate CVE-2026-53225
Sources
- https://git.kernel.org/stable/c/446e0ecd845abc394b24ae2030a883572bec9d16
- https://git.kernel.org/stable/c/8ce96f1182644079249a24ac7e2ffc32e0301a46
- https://git.kernel.org/stable/c/8e86817b8af4d552f3c6fe04ca52bb0c8c57411d
- https://git.kernel.org/stable/c/928dd94db23e8ba340f83d68f7f24d831b7a4426
- https://git.kernel.org/stable/c/d6bd0bb7697ea8c0387b0d9d973453f479017b23
- https://git.kernel.org/stable/c/d796cfd06074b579d265b28401306cadd30db945
- https://git.kernel.org/stable/c/f76a8b323e28e0951f979dbef20a7496383c47df
- https://git.kernel.org/stable/c/f8373d7090b745728de66308deeecc67e8d319ce