Junglewise Threat Intelligence

CVE-2026-53224: Linux Kernel out-of-bounds read in SCTP cookie processing

CVE-2026-53224 · Severity: info · CVSS 0 · Published 2026-06-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking stack could allow a remote attacker to cause system instability or leak sensitive information. The issue exists in how the system processes specific SCTP network packets, which are often used in telephony and signaling environments. By sending a specially crafted packet, an attacker can trigger an error that reads data outside of the intended memory boundaries.

Technical details

An out-of-bounds read vulnerability exists in the Linux kernel's SCTP implementation within net/sctp/sm_make_chunk.c and net/sctp/bind_addr.c. The function sctp_unpack_cookie() failed to verify that the embedded INIT chunk was large enough to contain a full header and did not properly validate the raw_addr_list_len against the cookie payload. A remote attacker can send a malformed COOKIE_ECHO chunk to trigger out-of-bounds reads during INIT parameter processing or address parsing. Patches have been released for various stable branches including 6.18.36 and 7.0.13.

Affected products

  • Linux Linux 2.6.12 through 6.18.35, 7.0.12

Timeline

  • 2026-06-07: other: Patch authored
  • 2026-06-25: advisory: CVE published

References