Executive brief
A vulnerability was identified in the Linux kernel's implementation of the SCTP protocol, which is used for transporting data over networks. An attacker could send a specially crafted network packet to trigger a memory leak, potentially exposing sensitive information from the system's memory to the attacker. This issue affects systems running Linux that have SCTP enabled, including those where unprivileged users can create network connections.
Technical details
An information disclosure vulnerability exists in the Linux kernel SCTP implementation within the `sctp_sf_do_5_2_6_stale()` function. When processing an ERROR chunk with a STALE_COOKIE cause in the COOKIE_ECHOED state, the kernel attempts to read a 4-byte 'Measure of Staleness' value without verifying that the cause length is sufficient to contain it. Because `sctp_walk_errors()` only validates the 4-byte header, a malformed chunk can cause the kernel to read past the intended buffer or the `skb->tail`. This uninitialized memory is then echoed back to the peer in the 'Cookie Preservative' field of a reply INIT packet. The vulnerability is reachable by any remote peer or local unprivileged process capable of initiating an SCTP association. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel All versions prior to fixed stable releases (e.g., 6.10, 6.6, 6.1, 5.15, 5.10, 5.4, 4.19)
Timeline
- 2026-07-03: disclosed: Initial patch submission by Weiming Shi
- 2026-07-10: patched: Patch committed to stable tree by Paolo Abeni
- 2026-07-27: advisory: CVE-2026-64551 published
References
- https://git.kernel.org/stable/c/08a8f2d13f703924316e9aeac863a88ef50990c7
- https://git.kernel.org/stable/c/1cd23ca80784223fa2204e16203f754da4e821f8
- https://git.kernel.org/stable/c/588706ebaf8cdb4a4161602949eba365514b1db1
- https://git.kernel.org/stable/c/6022da37786701df1fc5dd946a6dcba59d5473b1
- https://git.kernel.org/stable/c/861f884f5471632c731cbbd612a1c072e391a624
- https://git.kernel.org/stable/c/a257b41ddfe9e327b26581ad2777f04b23ac73f5
- https://git.kernel.org/stable/c/bbd6b2ea966cf57b6ae095cf5a8dbc993cd197a0