SCTP Association Lookup Vulnerability in illumos Product
CVE-2026-15422

9.1CRITICAL

Key Information:

Vendor

Illumos

Vendor
CVE Published:
16 July 2026

What is CVE-2026-15422?

The illumos SCTP implementation contains a critical vulnerability during the association lookup process for INIT ACK chunks. The flaw arises from insufficient validation of address parameters within these chunks. This occurs during packet classification, which precedes the application of SCTP integrity checks or IPsec policies. As a result, an unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted SCTP INIT ACK packet with malformed address parameters. This can lead to out-of-bounds access and kernel heap corruption, potentially allowing an attacker to execute arbitrary code remotely. The vulnerability has been present in illumos since 2010 and affects all distributions up until the specified commit.

Affected Version(s)

illumos-gate a5407c02d5ed61b29481b9b71f1307d7ebec9e5c

OmniOS r151058

OmniOS r151058

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sourque
Dan McDonald
.