A critical vulnerability tracked as CVE-2026-15422 was disclosed in the illumos SCTP stack, where improper validation of INIT ACK chunk address parameters can let a remote, unauthenticated attacker trigger kernel heap corruption and potentially achieve remote code execution. The flaw affects the SCTP inbound path because association lookup for INIT ACK traffic occurs before SCTP integrity checks and before IPsec policy is applied, expanding exposure for systems that process crafted network packets. The issue has reportedly existed since a 2010 illumos-gate commit and impacts illumos-based platforms including downstream distributions such as SmartOS.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-15422 was publicly listed as a critical illumos SCTP vulnerability with CVSS 9.1, describing how remote unauthenticated attackers could trigger kernel heap corruption and potentially achieve remote code execution on affected illumos distributions.
The CVE record states the SCTP flaw has existed since 2010, when illumos-gate commit a5407c02 introduced the vulnerable INIT ACK association lookup behavior without sufficient address parameter validation.
A fix for bug #18117 was published in illumos-gate as commit 53a3efde, adding stricter validation for SCTP INIT ACK chunk and address parameter handling to prevent malformed traffic from triggering unsafe processing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceillumos.org
Open sourceillumos.topicbox.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.