Executive brief
A vulnerability exists in the SCTP networking component of illumos-based operating systems, which are used for server and cloud infrastructure. An attacker can send a specially crafted network packet to crash the system or potentially take full control of the server. This occurs before standard security checks are applied, meaning even systems with firewalls or encryption enabled may be vulnerable.
Technical details
A heap-based buffer overflow (CWE-122) and out-of-bounds write (CWE-787) exist in the illumos SCTP implementation, specifically within the `sctp_lookup_by_faddrs` function in `sctp_hash.c`. The flaw occurs because the inbound path performs association lookups for INIT ACK chunks without validating address parameters during the packet classification phase. Because this lookup happens before SCTP integrity checks or IPsec policies are enforced, a remote unauthenticated attacker can trigger kernel heap corruption. This can result in a kernel panic (denial of service) or remote code execution. The vulnerability has been patched in illumos-gate commit 53a3efde and corresponding downstream distributions.
Affected products
- illumos illumos-gate a5407c02 to 53a3efde
- OmniOS OmniOS Prior to r151058j, r151056aj, or r151054bj
- Triton Data Center SmartOS Prior to 20260709
Timeline
- 2010: other: Vulnerability introduced in commit a5407c02
- 2026-07-08: patched: Fix committed to illumos-gate repository
- 2026-07-16: advisory: CVE-2026-15422 published