CVE-2026-15422
CRITICALSCTP needs to better-check INIT ACK chunk parameters
Title source: cnaDescription
The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs during packet classification (i.e. before SCTP integrity checks or IPsec policy are applied) a remote, unauthenticated attacker can send a crafted SCTP INIT ACK packet with malformed address parameters to cause an out-of-bounds access and kernel heap corruption, which may lead to remote code execution. The flaw has existed since 2010 (illumos-gate commit a5407c02), and affects any illumos distribution prior to illumos-gate commit 53a3efde.
References (3)
Core 3
Core References
Mailing List mailing-list
https://illumos.topicbox.com/groups/developer/Ta1a8e2e1f7f928df/18117-sctp-needs-to-better-check-init-ack-chunk-parameters
Issue Tracking issue-tracking
https://illumos.org/issues/18117
Scores
CVSS v4
9.1
EPSS
0.0051
EPSS Percentile
40.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:H/U:Red
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-122
CWE-787
Status
published
Products (6)
illumos/illumos-gate
a5407c02d5ed61b29481b9b71f1307d7ebec9e5c - 53a3efdeff8e6745bbfb69c5360f94962fb79e75
OmniOS/OmniOS
any - r151054
OmniOS/OmniOS
r151054 - r151054bj
OmniOS/OmniOS
r151056 - r151056aj
OmniOS/OmniOS
r151058 - r151058j
Triton Data Center/SmartOS
any - 202060709
Published
Jul 16, 2026
Tracked Since
Jul 17, 2026