PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-53004 Linux CVE debrief

A Linux kernel vulnerability was found in the SCTP implementation. The issue occurs in the sctp_getsockopt_peer_auth_chunks function, where an out-of-bounds write to userspace can happen. This happens because the function checks if the provided buffer is large enough for the peer's AUTH chunk list but does not account for the size of the struct sctp_authchunks header. An unprivileged userspace caller can exploit this by providing a short buffer, leading to the overwrite of adjacent userspace data with the peer's AUTH chunk type.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-24
Original CVE updated
2026-07-14
Advisory published
2026-06-24
Advisory updated
2026-07-14

Who should care

Linux kernel users and administrators should be aware of this vulnerability, especially those using SCTP with AUTH enabled. This vulnerability can lead to silent corruption of userspace data.

Technical summary

The sctp_getsockopt_peer_auth_chunks function in the Linux kernel's SCTP implementation does not properly validate the provided buffer size. Specifically, it checks if the buffer length is less than the number of chunks but does not account for the 8-byte header of the struct sctp_authchunks. This can lead to an out-of-bounds write when the caller provides a buffer that is too small. The vulnerability can be exploited by an unprivileged userspace caller that has opened a loopback SCTP association with AUTH enabled.

Defensive priority

High

Recommended defensive actions

  • Apply the kernel patch that fixes the sctp_getsockopt_peer_auth_chunks function
  • Review and update SCTP configurations to ensure proper buffer sizing
  • Monitor systems for unusual behavior related to SCTP and AUTH chunks
  • Perform a thorough review of system logs to identify potential exploitation attempts
  • Implement additional monitoring to detect anomalies in SCTP traffic
  • Verify that all SCTP associations are properly configured and validated
  • Check for any unauthorized changes to SCTP configuration files

Evidence notes

The vulnerability was resolved in the Linux kernel. The fix aligns the peer variant of the function with its sibling, sctp_getsockopt_local_auth_chunks, which already had the correct check. Reproducer code confirms the vulnerability on affected systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-53004 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-53004

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-53004 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53004

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0cf004ffb61cd32d140531c3a84afe975f9fc7ea

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2b5a2c957c7769d40110f725cf23987fcef50d75

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6849b995cda88a677bf08a05765d1db7905974fc

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6bcf8fe4ef7967b22b814cbae9a57bbd3c853410

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/70a089cc9590aa347a61e84434116ab74619e3c3

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a132e199de69e2a45628aa8534df1bf5d44e1b6e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d45c7e99caf915b0f6c716bd8ffe9d45b9685761

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.