SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-64551

CRITICAL · CVSS 9.1 EPSS 0.51%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the Stream Control Transmission Protocol (SCTP) implementation, where improper validation of the STALE_COOKIE cause length can lead to reading beyond allocated memory, resulting in the potential leakage of uninitialized memory contents. This critical flaw can be exploited by any peer capable of initiating an SCTP association in the COOKIE_ECHOED state, including unprivileged processes using raw SCTP sockets. Organizations using Linux systems that implement SCTP should prioritize patching this vulnerability to mitigate the risk of data leakage.

CVE
CVE-2026-64551
Severity
CRITICAL
CVSS
9.1
EPSS
0.51%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: sctp: validate STALE_COOKIE cause length before reading staleness When an ERROR chunk with a STALE_COOKIE cause is received in the COOKIE_ECHOED state, sctp_sf_do_5_2_6_stale() reads the 4-byte Measure of Staleness that follows the cause header: err = (struct sctp_errhdr *)(chunk->skb->data); stale = ntohl(*(__be32 *)((u8 *)err + sizeof(*err))); err is the first cause in the chunk, not the STALE_COOKIE cause that caused the dispatch, and nothing guarantees the staleness field is present. sctp_walk_errors() only requires a cause to be as long as the 4-byte header, so for a STALE_COOKIE cause of length 4 the read runs past the cause, and for a minimal ERROR chunk past skb->tail. The value is echoed to the peer in the Cookie Preservative of the reply INIT, leaking uninitialized memory. sctp_sf_cookie_echoed_err() already walks to the STALE_COOKIE cause, so check its length there and pass it to sctp_sf_do_5_2_6_stale(), which reads that cause instead of the first one. A STALE_COOKIE cause too short to hold the staleness field is discarded. The read is reachable by any peer that can drive an association into COOKIE_ECHOED, including an unprivileged process using a raw SCTP socket in a user and network namespace.