CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
In the Linux kernel, the following vulnerability has been resolved:
Other sources
sctp: validate cached peer INIT chunk length in COOKIEECHO processing
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 7.2.6-1Fixed in 7.2.8-1 - Compensating control
Add a bounds check in Linux kernel sctp_unpack_cookie() to ensure the cached INIT chunk length does not exceed the remaining available data in the COOKIE_ECHO buffer before parsing or using the chunk.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53246?
The severity of CVE-2026-53246 is ranked at 51.
How do I fix CVE-2026-53246?
To fix CVE-2026-53246, update the Linux kernel to the latest version where this vulnerability has been resolved.
What systems are affected by CVE-2026-53246?
CVE-2026-53246 affects the Linux kernel that implements the SCTP protocol.
What type of vulnerability is CVE-2026-53246?
CVE-2026-53246 is a vulnerability related to improper validation of cached peer INIT chunk length during COOKIE_ECHO processing.
When was CVE-2026-53246 published?
CVE-2026-53246 was published on June 25, 2026.