Out-of-bounds read in Linux kernel - CVE-2026-98123
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to read memory out of bounds.
The vulnerability exists due to an out-of-bounds read in sctp_get_asconf_response() when processing a truncated SCTP_PARAM_ERR_CAUSE parameter in an ASCONF-ACK. A remote user can send a crafted ASCONF-ACK containing an error-cause parameter without a complete error header to read memory out of bounds.
The association must have ADD-IP enabled and an outstanding ASCONF request.