Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-15422— SCTP needs to better-check INIT ACK chunk parameters

Quick assessment

Affected
illumos illumos-gate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

illumos illumos-gate是illumos组织开源的一个开源 Unix 操作系统。 illumos illumos-gate存在缓冲区错误漏洞,该漏洞源于SCTP入站路径对INIT ACK数据块进行关联查找时未充分验证地址参数,可能导致远程、未验证的攻击者通过发送特制SCTP INIT ACK数据包触发越界访问和内核堆损坏,从而导致远程代码执行。以下版本受到影响:illumos-gate a5407c02版本至53a3efde版本、OmniOS r151058版本、r151056版本、r15

AI Predicted 9.8 Difficulty: Moderate EPSS 0.88% · P58

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 6

VendorProduct Version RangeStatus
illumos illumos-gate a5407c02d5ed61b29481b9b71f1307d7ebec9e5c< 53a3efdeff8e6745bbfb69c5360f94962fb79e75 affected
OmniOS OmniOS r151058< r151058j affected
r151056< r151056aj affected
r151054< r151054bj affected
any< r151054 affected
Triton Data Center SmartOS any< 202060709 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-15422

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SCTP needs to better-check INIT ACK chunk parameters
Source: CVE Program / CVE List V5
Vulnerability Description
The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs during packet classification (i.e. before SCTP integrity checks or IPsec policy are applied) a remote, unauthenticated attacker can send a crafted SCTP INIT ACK packet with malformed address parameters to cause an out-of-bounds access and kernel heap corruption, which may lead to remote code execution. The flaw has existed since 2010 (illumos-gate commit a5407c02), and affects any illumos distribution prior to illumos-gate commit 53a3efde.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/S:P/AU:Y/R:U/V:C/RE:H/U:Red
Source: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
Source: CVE Program / CVE List V5
Vulnerability Title
illumos illumos-gate 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
illumos illumos-gate是illumos组织开源的一个开源 Unix 操作系统。 illumos illumos-gate存在缓冲区错误漏洞,该漏洞源于SCTP入站路径对INIT ACK数据块进行关联查找时未充分验证地址参数,可能导致远程、未验证的攻击者通过发送特制SCTP INIT ACK数据包触发越界访问和内核堆损坏,从而导致远程代码执行。以下版本受到影响:illumos-gate a5407c02版本至53a3efde版本、OmniOS r151058版本、r151056版本、r15
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
illumos illumos-gate a5407c02d5ed61b29481b9b71f1307d7ebec9e5c ~ 53a3efdeff8e6745bbfb69c5360f94962fb79e75 -
OmniOS OmniOS r151058 ~ r151058j -
Triton Data Center SmartOS any ~ 202060709 -

II. Public POCs for CVE-2026-15422

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15422

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-15422 (1)

Mailing List Discussions for CVE-2026-15422 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-15422

No comments yet


Leave a comment