In the Linux kernel, the following vulnerability has been resolved:
sctp: prevent peer transport count overflow
sctp_assoc_add_peer() increments the association's 16-bit transport_count
for every new unique peer. Adding the 65,536th transport wraps the count to
zero.
SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
then copies one sockaddr_storage for every entry in transport_addr_list.
After the wrap, a diagnostic dump reserves an empty payload and writes
8 MiB of peer addresses past the skb tail.
Reject a new unique peer when transport_count has reached U16_MAX. Perform
the check after the existing-peer lookup so a duplicate address continues
to return its existing transport at the limit.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-15 13:17
Updated : 2026-08-19 17:21
NVD link : CVE-2026-74469
Mitre link : CVE-2026-74469
CVE.ORG link : CVE-2026-74469
JSON object : View
Products Affected
No product.
CWE
No CWE.
