CVE-2026-15422
CVE-2026-15422 is a critical vulnerability in illumos SCTP that allows remote attackers to trigger heap corruption via malformed INIT ACK packets, potentially leading to remote code execution. It stems from unvalidated address parameters during packet classification, existing since 2010. No affected products are listed, and no public exploit is known.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of illumos distributions prior to illumos-gate commit 53a3efde
Real-world impact
Remote code execution via crafted network packets
Why this severity
CVSS 9.1 (critical): High confidence in exploitability and severe impact
What to do about it
- ›Block or filter SCTP INIT ACK packets from untrusted sources at the network perimeter
- ›Apply the latest available illumos-gate commit (53a3efde or newer) if available
- ›Contact the illumos vendor for security updates or patches addressing this flaw
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
NVD description and vulnerability timeline data