← All Advisories

Linux Kernel SCTP ASCONF Chunk Processing Skips Length Validation of Embedded Address Parameters, Allowing Network-Controlled Data to Trigger Out-of-Bounds Reads

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-74287

Key Details

CVECVE-2026-74287
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-08-17
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.

What to Know

In the Linux kernel, the following vulnerability has been resolved:

sctp: validate embedded address parameter length

sctp_verify_asconf() and sctp_verify_param() only validate ADD_IP, DEL_IP,

and SET_PRIMARY parameters against a fixed minimum size of sizeof(struct

sctp_addip_param) + sizeof(struct sctp_paramhdr). This ensures the outer

parameter is large enough to contain an embedded address parameter header,

but does not verify that the embedded address parameter's declared length

fits within the bounds of the outer parameter.

Later, sctp_process_param() and sctp_process_asconf_param() extract the

embedded address parameter and pass it to af->from_addr_param(), which uses

the address parameter length to parse the variable-length address payload.

A malformed peer can therefore advertise an embedded address parameter

length that exceeds the remaining bytes in the enclosing parameter.

Validate that addr_param->p.length does not exceed the space available

after the sctp_addip_param header before processing the embedded address

parameter. Reject malformed parameters when the embedded address length

extends beyond the enclosing parameter bounds.

This prevents out-of-bounds reads when parsing malformed parameters carried

in INIT or ASCONF processing paths. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-74287
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-74287