-

CVE-2026-98123

sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration

In the Linux kernel, the following vulnerability has been resolved:

sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration

sctp_verify_asconf() walks ASCONF-ACK parameters with
sctp_walk_params(), which advances by SCTP_PAD4(length), while the
consumer sctp_get_asconf_response() iterates the same parameters
advancing by the raw length, without padding. A single odd-length
parameter desynchronises the two walks and makes the consumer
interpret attacker-controlled bytes at a misaligned offset.

When those bytes yield a length of zero, the while loop over
asconf_ack_len makes no progress, spinning forever in softirq
context, and the watchdog reports a soft lockup. All reads stay
within the received skb, so the lockup is a pure remote denial of
service. A remote peer can trigger it with a crafted ASCONF-ACK on
an ADD-IP enabled association with an outstanding ASCONF (RFC 5061
section 4.1.2 requires the chunk to be authenticated, but the
predefined empty key id 0 allows the peer to compute the same
association HMAC from publicly exchanged parameters, so the gate
does not help).

The SCTP_PARAM_ERR_CAUSE case of sctp_verify_asconf() also performs
no length check, letting a parameter without a complete error
header reach the consumer, which reads errhdr.cause past the end of
the parameter, an out-of-bounds read.

Reject SCTP_PARAM_ERR_CAUSE parameters shorter than
sizeof(struct sctp_addip_param) + sizeof(struct sctp_errhdr) at the
verifier, and advance the consumer iterator with the same padding
rule as the verifier to keep the two walks in lockstep. The verifier
change guarantees a complete error header in every ERR_CAUSE
parameter the consumer can see, so the consumer's asconf_ack_len
check is dropped and it returns err_param->cause directly. The
consumer padding fix is still required because odd lengths remain
valid for SCTP_PARAM_ERR_CAUSE per RFC 5061.

The issue was found by ZeroHive, a vulnerability hunting agent at
Tencent Yunding Lab.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < ba54cad229977f4fae6355dbdaf117088414fdd0
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 7d8e7ab6a0665888beee91f7ad77ac805963c4fd
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 5fbc6a778d5fce7628821236972596acb18e1065
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 4548d843e7b29f6d150d8caae4e64015fa226b0c
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < abf59d7f6fff23227256e8199aca5ade45758f8b
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 3be02999ab9131a4b96eb1eda4ca48b1cea80f03
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 7ba84e2971d208a2d6413a334ec28a8a32cdce0f
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 2cb0b0b1ed69430bf73740377ea0a1c44c50db63
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.055
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/abf59d7f6fff23227256e8199aca5ade45758f8b
https://git.kernel.org/stable/c/3be02999ab9131a4b96eb1eda4ca48b1cea80f03
https://git.kernel.org/stable/c/7ba84e2971d208a2d6413a334ec28a8a32cdce0f
https://git.kernel.org/stable/c/2cb0b0b1ed69430bf73740377ea0a1c44c50db63
https://git.kernel.org/stable/c/4548d843e7b29f6d150d8caae4e64015fa226b0c
https://git.kernel.org/stable/c/5fbc6a778d5fce7628821236972596acb18e1065
https://git.kernel.org/stable/c/7d8e7ab6a0665888beee91f7ad77ac805963c4fd
https://git.kernel.org/stable/c/ba54cad229977f4fae6355dbdaf117088414fdd0