CVE-2026-15422: SCTP needs to better-check INIT ACK chunk parameters
The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs during packet classification (i.e. before SCTP integrity checks or IPsec policy are applied) a remote, unauthenticated attacker can send a crafted SCTP INIT ACK packet with malformed address parameters to cause an out-of-bounds access and kernel heap corruption, which may lead to remote code execution. The flaw has existed since 2010 (illumos-gate commit a5407c02), and affects any illumos distribution prior to illumos-gate commit 53a3efde.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
illumos distro (SCTP inbound path)to a version that resolves this vulnerability.Patch 18117 - Compensating control
As a mitigation until the illumos update including 18117's fix is applied, block inbound SCTP traffic at the network perimeter (e.g., firewall/ACL) to prevent unauthenticated attackers from sending crafted SCTP INIT ACK packets.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15422?
CVE-2026-15422 has a critical severity rating of 9.1 according to the CVSS.”},{