Linux Kernel Vulnerability in SCTP Handling
CVE-2026-64551

9.1CRITICAL

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-64551?

A vulnerability exists in the Linux kernel's SCTP module, where improper validation occurs when handling ERROR chunks with STALE_COOKIE causes. An attacker can exploit this flaw to read potentially sensitive data from uninitialized memory, leading to a data leak. The issue arises during the processing of the 4-byte Measure of Staleness, particularly when the staleness field is not properly validated beforehand. As such, unprivileged processes could inadvertently access this memory, potentially resulting in unintended information disclosure.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6022da37786701df1fc5dd946a6dcba59d5473b1

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 861f884f5471632c731cbbd612a1c072e391a624

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 588706ebaf8cdb4a4161602949eba365514b1db1

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.