KernelScan.io

HIGH Public exploit Introduced in 4.7

DiagSpill

CVE-2026-74469

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.7HIGH

01

In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport count overflow sctp_assoc_add_peer() increments the association's 16-bit transport_count for every new unique peer. Adding the 65,536th transport wraps the count to zero. SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload, then copies one sockaddr_storage for every entry in transport_addr_list. After the wrap, a diagnostic dump reserves an empty payload and writes 8 MiB of peer addresses past the skb tail. Reject a new unique peer when transport_count has reached U16_MAX. Perform the check after the existing-peer lookup so a duplicate address continues to return its existing transport at the limit.

02

Engine v0.6.0

Risk summary

A local unprivileged user can overflow a 16-bit peer transport counter in an SCTP association, causing a subsequent diagnostic dump to write approximately 8 MiB of peer address data past the end of a kernel buffer. This results in kernel heap corruption that can lead to arbitrary read/write capability or a system crash. A remote SCTP peer can also set up the overflow condition on a server that accepts SCTP connections, though triggering the actual memory corruption still requires a local diagnostic query.

Affectednet/sctp/associola.c (sctp)

Vulnerability analysis

The SCTP association handling increments a 16-bit counter each time a new peer transport address is added, without checking for overflow. When the counter wraps to zero on the 65,536th addition, a subsequent diagnostic dump via the NETLINK socket interface reserves buffer space based on the wrapped (zero) count but then copies all stored peer addresses into the undersized buffer, writing approximately 8 MiB past the buffer boundary. The fix rejects new peer additions once the counter reaches its maximum value, preventing the wrap from ever occurring. The overflow can be set up by any local user with an SCTP socket or by a remote SCTP peer supplying many addresses during association establishment on a server that accepts SCTP connections; the resulting out-of-bounds write is triggered when a local diagnostic dump is performed, which any local user can initiate via NETLINK.

Exploit availability

KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.

03

BranchIntroducedFixed inPatch commit
5.104.75.10.265b453e00da121
6.64.76.6.151546221b86cee
6.124.76.12.10309e722030e81
6.184.76.18.444ba5bf7ed50f
7.14.77.1.86201cd1d70f1
mainline4.77.2bd0e9289e264
6.14.76.1.18380f48523a0fe
5.154.75.15.216dfea32dd76f3