CVE-2026-15422

CRITICAL

SCTP needs to better-check INIT ACK chunk parameters

Title source: cna
STIX 2.1

Description

The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs during packet classification (i.e. before SCTP integrity checks or IPsec policy are applied) a remote, unauthenticated attacker can send a crafted SCTP INIT ACK packet with malformed address parameters to cause an out-of-bounds access and kernel heap corruption, which may lead to remote code execution. The flaw has existed since 2010 (illumos-gate commit a5407c02), and affects any illumos distribution prior to illumos-gate commit 53a3efde.

Scores

CVSS v4 9.1
EPSS 0.0051
EPSS Percentile 40.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:H/U:Red

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-122 CWE-787
Status published
Products (6)
illumos/illumos-gate a5407c02d5ed61b29481b9b71f1307d7ebec9e5c - 53a3efdeff8e6745bbfb69c5360f94962fb79e75
OmniOS/OmniOS any - r151054
OmniOS/OmniOS r151054 - r151054bj
OmniOS/OmniOS r151056 - r151056aj
OmniOS/OmniOS r151058 - r151058j
Triton Data Center/SmartOS any - 202060709
Published Jul 16, 2026
Tracked Since Jul 17, 2026