CVE-2026-15422: SCTP needs to better-check INIT ACK chunk parameters

Published Jul 16, 2026
·
Updated

The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs during packet classification (i.e. before SCTP integrity checks or IPsec policy are applied) a remote, unauthenticated attacker can send a crafted SCTP INIT ACK packet with malformed address parameters to cause an out-of-bounds access and kernel heap corruption, which may lead to remote code execution. The flaw has existed since 2010 (illumos-gate commit a5407c02), and affects any illumos distribution prior to illumos-gate commit 53a3efde.

Affected Software

1 affected component
illumos SCTP<illumos-gate commit 53a3efde

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade illumos distro (SCTP inbound path) to a version that resolves this vulnerability.

    Patch 18117
  2. Compensating control

    As a mitigation until the illumos update including 18117's fix is applied, block inbound SCTP traffic at the network perimeter (e.g., firewall/ACL) to prevent unauthenticated attackers from sending crafted SCTP INIT ACK packets.

Event History

Jul 16, 2026
CVE Published
via MITRE·07:29 PM
Data Sourced
via MITRE·07:29 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-15422?

CVE-2026-15422 has a critical severity rating of 9.1 according to the CVSS.”},{

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203