{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64551","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T15:36:31.796Z","datePublished":"2026-07-27T20:10:40.012Z","dateUpdated":"2026-08-17T04:57:28.771Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T04:57:28.771Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate STALE_COOKIE cause length before reading staleness\n\nWhen an ERROR chunk with a STALE_COOKIE cause is received in the\nCOOKIE_ECHOED state, sctp_sf_do_5_2_6_stale() reads the 4-byte Measure\nof Staleness that follows the cause header:\n\n\terr   = (struct sctp_errhdr *)(chunk->skb->data);\n\tstale = ntohl(*(__be32 *)((u8 *)err + sizeof(*err)));\n\nerr is the first cause in the chunk, not the STALE_COOKIE cause that\ncaused the dispatch, and nothing guarantees the staleness field is\npresent. sctp_walk_errors() only requires a cause to be as long as the\n4-byte header, so for a STALE_COOKIE cause of length 4 the read runs\npast the cause, and for a minimal ERROR chunk past skb->tail. The value\nis echoed to the peer in the Cookie Preservative of the reply INIT,\nleaking uninitialized memory.\n\nsctp_sf_cookie_echoed_err() already walks to the STALE_COOKIE cause, so\ncheck its length there and pass it to sctp_sf_do_5_2_6_stale(), which\nreads that cause instead of the first one. A STALE_COOKIE cause too\nshort to hold the staleness field is discarded.\n\nThe read is reachable by any peer that can drive an association into\nCOOKIE_ECHOED, including an unprivileged process using a raw SCTP socket\nin a user and network namespace."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":9.1,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The vulnerable code is in the SCTP receive-side state machine and is driven entirely by an attacker-crafted ERROR chunk arriving over the network; no local access is needed. Per kernel guidance, net/ stack bugs reachable via received packets (SCTP explicitly) are Network.\nAC:L - The attacker fully controls the trigger: acting as the SCTP peer it answers INIT with INIT-ACK to place the association in COOKIE_ECHOED, then sends a minimal ERROR chunk with a 4-byte STALE_COOKIE cause as the last chunk in the packet. There is no race, no memory-layout dependency, and the vtag needed is the one the victim itself advertised in its INIT.\nPR:N - SCTP association setup is unauthenticated; the only check is sctp_vtag_verify() against a tag the peer already received in the victim's INIT. The attacker needs no credentials or privileges on the target system.\nUI:N - No human user action is required — SCTP client daemons (SIGTRAN, Diameter, cluster transports) establish and retry associations automatically, and an on-path attacker can inject the ERROR into an in-progress handshake. In the local variant an unprivileged process creates both sides itself with no user involved.\nS:U - The out-of-bounds read and the resulting disclosure stay within the kernel's own security authority; no VM, sandbox, or IOMMU boundary is crossed.\nC:H - Uninitialized kernel memory past skb->tail is read and then transmitted straight back to the attacker inside the reply INIT's Cookie Preservative parameter, and the attack can be repeated indefinitely to sample recycled network-buffer memory that may contain remnants of other connections' traffic. This is a remote, unauthenticated, repeatable kernel heap disclosure oracle, matching the C:H treatment given to the sibling SCTP uninit-read CVE-2026-53225.\nI:N - The bug is a pure read; nothing in kernel memory or in the victim's association state is modified. The only affected value is a protocol field in a packet sent to the attacker itself.\nA:H - The read runs past the end of the received packet data, a memory-safety violation whose target is not proven to remain inside the skb's allocation across all receive paths (GSO/frag_list segments, UDP-encapsulated and linearized skbs), so it can fault and oops; kernel guidance and the CNA's scoring of the equivalent SCTP out-of-bounds-read bug both treat this class as A:H."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sctp/sm_statefuns.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6022da37786701df1fc5dd946a6dcba59d5473b1","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"861f884f5471632c731cbbd612a1c072e391a624","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"588706ebaf8cdb4a4161602949eba365514b1db1","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a257b41ddfe9e327b26581ad2777f04b23ac73f5","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"08a8f2d13f703924316e9aeac863a88ef50990c7","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ebe0a55d954fa8da383b6192edb8f763dcb002d5","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bbd6b2ea966cf57b6ae095cf5a8dbc993cd197a0","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1cd23ca80784223fa2204e16203f754da4e821f8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sctp/sm_statefuns.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6022da37786701df1fc5dd946a6dcba59d5473b1"},{"url":"https://git.kernel.org/stable/c/861f884f5471632c731cbbd612a1c072e391a624"},{"url":"https://git.kernel.org/stable/c/588706ebaf8cdb4a4161602949eba365514b1db1"},{"url":"https://git.kernel.org/stable/c/a257b41ddfe9e327b26581ad2777f04b23ac73f5"},{"url":"https://git.kernel.org/stable/c/08a8f2d13f703924316e9aeac863a88ef50990c7"},{"url":"https://git.kernel.org/stable/c/ebe0a55d954fa8da383b6192edb8f763dcb002d5"},{"url":"https://git.kernel.org/stable/c/bbd6b2ea966cf57b6ae095cf5a8dbc993cd197a0"},{"url":"https://git.kernel.org/stable/c/1cd23ca80784223fa2204e16203f754da4e821f8"}],"title":"sctp: validate STALE_COOKIE cause length before reading staleness","x_generator":{"engine":"bippy-1.2.0"}}}}