Linux Kernel Vulnerability in SCTP Handling
CVE-2026-64551
What is CVE-2026-64551?
A vulnerability exists in the Linux kernel's SCTP module, where improper validation occurs when handling ERROR chunks with STALE_COOKIE causes. An attacker can exploit this flaw to read potentially sensitive data from uninitialized memory, leading to a data leak. The issue arises during the processing of the 4-byte Measure of Staleness, particularly when the staleness field is not properly validated beforehand. As such, unprivileged processes could inadvertently access this memory, potentially resulting in unintended information disclosure.
Affected Version(s)
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6022da37786701df1fc5dd946a6dcba59d5473b1
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 861f884f5471632c731cbbd612a1c072e391a624
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 588706ebaf8cdb4a4161602949eba365514b1db1