Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-53224

CRITICAL · 9.1 CVSS Gepubliceerd: CWE-125

Beschrijving NL

In de Linux kernel is de volgende kwetsbaarheid verholpen:

sctp: valideer ingebedde INIT chunk- en adreslijstlengtes in cookie

sctp_unpack_cookie() heeft alleen gecontroleerd of de ingebedde INIT CHUNK-LENGTE
de resterende cookielading niet heeft overschreden, maar er niet voor heeft gezorgd dat de
INIT chunk is groot genoeg om een volledige INIT header te bevatten. Een misvormde COOKIE_ECHO kan daarom een afgeknotte INIT chunk dragen waarvan
lengteveld kleiner is dan sizeof(struct sctp_init_chunk). Later,
sctp_process_init() heeft onvoorwaardelijk toegang tot init-parameters, die mogelijk
leiden tot out-of-bounds lezen. Bovendien is RAW_addr_list_len niet volledig gevalideerd tegen de
resterende cookie-payload. Wanneer cookie-authenticatie is uitgeschakeld, wordt een
aanvaller kan een te grote RAW_addr_list_len en oorzaak
sctp_raw_to_bind_addrs () om verder te lezen dan het einde van de cookie. De
adresparser mist ook voldoende grenscontroles voor parameterkoppen
en lengtes, waardoor onjuiste adresparameters kunnen worden geactiveerd
out-of-bounds leest. Los dit op door:

- waarbij de ingebedde INIT chunk-lengte ten minste de grootte moet hebben van (struct
sctp_init_chunk);
- valideren dat de INIT chunk en ruwe adreslijst samen passen
binnen de cookie-payload;
- controleren of er voldoende gegevens zijn voor elke adresparameterkop en
lading voordat deze wordt geparseerd. Merk op dat sctp_verify_init() moet worden aangeroepen na sctp_unpack_cookie()
en vóór sctp_process_init() wanneer cookie-authenticatie is uitgeschakeld. Dit zal in een aparte patch worden aangepakt.

Origineel (Engels) tonen

In the Linux kernel, the following vulnerability has been resolved:

sctp: validate embedded INIT chunk and address list lengths in cookie

sctp_unpack_cookie() only checked that the embedded INIT chunk length
did not exceed the remaining cookie payload, but did not ensure that the
INIT chunk is large enough to contain a complete INIT header.

A malformed COOKIE_ECHO can therefore carry a truncated INIT chunk whose
length field is smaller than sizeof(struct sctp_init_chunk). Later,
sctp_process_init() accesses INIT parameters unconditionally, which may
lead to out-of-bounds reads.

In addition, raw_addr_list_len is not fully validated against the
remaining cookie payload. When cookie authentication is disabled, an
attacker can supply an oversized raw_addr_list_len and cause
sctp_raw_to_bind_addrs() to read beyond the end of the cookie. The
address parser also lacks sufficient bounds checks for parameter headers
and lengths, allowing malformed address parameters to trigger
out-of-bounds reads.

Fix this by:

- requiring the embedded INIT chunk length to be at least sizeof(struct
sctp_init_chunk);
- validating that the INIT chunk and raw address list together fit
within the cookie payload;
- verifying sufficient data exists for each address parameter header and
payload before parsing it.

Note that sctp_verify_init() must be called after sctp_unpack_cookie()
and before sctp_process_init() when cookie authentication is disabled.
This will be addressed in a separate patch.

Vendors

Linux

Affected products

Linux Kernel

References