UBUNTU-CVE-2026-53225

    Dashboard / Vulnerabilities / UBUNTU-CVE-2026-53225

    UBUNTU-CVE-2026-53225

    Published: 25 Jun 2026Last Modified: 25 Sept 2026
    Upstream:
    Aliases:

    Summary:

    Details: In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header; reached from the no-association lookup path, from_addr_param() then reads uninitialized bytes past the parameter. Impact: an unauthenticated SCTP peer makes the receive path read up to 16 bytes of uninitialized memory past a truncated ASCONF address parameter. The sibling __sctp_rcv_init_lookup() bounds parameters with sctp_walk_params(); this path open-codes the fetch and omits the bound. Verify the whole address parameter lies within the chunk before from_addr_param() reads it, the same class of fix as commit 51e5ad549c43 ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").

    References: https://ubuntu.com/security/CVE-2026-53225, https://www.cve.org/CVERecord?id=CVE-2026-53225, https://git.kernel.org/linus/f8373d7090b745728de66308deeecc67e8d319ce, https://git.kernel.org/stable/c/446e0ecd845abc394b24ae2030a883572bec9d16, https://git.kernel.org/stable/c/8ce96f1182644079249a24ac7e2ffc32e0301a46, https://git.kernel.org/stable/c/8e86817b8af4d552f3c6fe04ca52bb0c8c57411d, https://git.kernel.org/stable/c/928dd94db23e8ba340f83d68f7f24d831b7a4426, https://git.kernel.org/stable/c/d6bd0bb7697ea8c0387b0d9d973453f479017b23, https://git.kernel.org/stable/c/d796cfd06074b579d265b28401306cadd30db945, https://git.kernel.org/stable/c/f76a8b323e28e0951f979dbef20a7496383c47df, https://git.kernel.org/stable/c/f8373d7090b745728de66308deeecc67e8d319ce, https://ubuntu.com/security/notices/USN-8629-1, https://ubuntu.com/security/notices/USN-8630-1, https://ubuntu.com/security/notices/USN-8631-1, https://ubuntu.com/security/notices/USN-8633-1, https://ubuntu.com/security/notices/USN-8634-1, https://ubuntu.com/security/notices/USN-8635-1, https://ubuntu.com/security/notices/USN-8636-1, https://ubuntu.com/security/notices/USN-8630-2, https://ubuntu.com/security/notices/USN-8631-2, https://ubuntu.com/security/notices/USN-8637-1, https://ubuntu.com/security/notices/USN-8631-3, https://ubuntu.com/security/notices/USN-8633-2, https://ubuntu.com/security/notices/USN-8629-2, https://ubuntu.com/security/notices/USN-8631-4, https://ubuntu.com/security/notices/USN-8645-1, https://ubuntu.com/security/notices/USN-8629-3, https://ubuntu.com/security/notices/USN-8630-3, https://ubuntu.com/security/notices/USN-8636-2, https://ubuntu.com/security/notices/USN-8656-1, https://ubuntu.com/security/notices/USN-8660-1, https://ubuntu.com/security/notices/USN-8661-1, https://ubuntu.com/security/notices/USN-8630-4, https://ubuntu.com/security/notices/USN-8662-1, https://ubuntu.com/security/notices/USN-8663-1, https://ubuntu.com/security/notices/USN-8664-1, https://ubuntu.com/security/notices/USN-8662-2, https://ubuntu.com/security/notices/USN-8669-1, https://ubuntu.com/security/notices/USN-8661-2, https://ubuntu.com/security/notices/USN-8630-5, https://ubuntu.com/security/notices/USN-8661-3, https://ubuntu.com/security/notices/USN-8661-4, https://ubuntu.com/security/notices/USN-8714-1, https://ubuntu.com/security/notices/USN-8715-1, https://ubuntu.com/security/notices/USN-8714-2, https://ubuntu.com/security/notices/USN-8728-1, https://ubuntu.com/security/notices/USN-8714-3, https://ubuntu.com/security/notices/USN-8715-2, https://ubuntu.com/security/notices/USN-8661-5, https://ubuntu.com/security/notices/USN-8728-2

    Affected packages

    Package

    Name: linux

    Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.13.0-215.266

    Affected versions

    3.11.0-12.19

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    UBUNTU-CVE-2026-53225 | CVE-DB