CVE-2026-15422
The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs during packet classification (i.e. before SCTP integrity checks or IPsec policy are applied) a remote, unauthenticated attacker can send a crafted SCTP INIT ACK packet with malformed address parameters to cause an out-of-bounds access and kernel heap corruption, which may lead to remote code execution. The flaw has existed since 2010 (illumos-gate commit a5407c02), and affects any illumos distribution prior to illumos-gate commit 53a3efde.
Published:Jul 16, 2026
Last Modified:Jul 30, 2026
EPS:Jul 16, 2026
EPSS Score:0.00508
CVSS Score:9.1
Affected Products
Vendor
Product
Action
Vendor
Illumos
Product
Illumos-gate
Illumos
Illumos-gate
Vendor
Omnios
Product
Omnios
Omnios
Omnios
Vendor
Tritondatacenter
Product
Smartos
Tritondatacenter
Smartos
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
