Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2026-74469 — Research repository for CVE-2026-74469 (DiagSpill), a Linux kernel SCTP peer transport counter overflow causing an out-of-bounds write, with PoC, root-cause analysis, and patch details. | Kitploit
उपकरण/GitHubGitHub/0xblackash/cve-2026-74469
Privilege EscalationMemory ForensicsVulnerability AnalysisExploitationPapers & ResearchLearning & EducationBinary ExploitationLabs & Practice
GitHub0xblackash/cve-2026-74469

CVE-2026-74469

Research repository for CVE-2026-74469 (DiagSpill), a Linux kernel SCTP peer transport counter overflow causing an out-of-bounds write, with PoC, root-cause analysis, and patch details.

16711 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
रिपॉजिटरी देखें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

⚡ CVE-2026-74469 — DiagSpill

Gemini_Generated_Image_yv49p8yv49p8yv49

Linux Kernel SCTP Peer Transport Count Overflow

A Linux kernel SCTP vulnerability caused by a 16-bit peer transport counter overflow, allowing the counter to wrap from 65535 to 0. During an SCTP diagnostic dump, the wrapped value can cause insufficient skb payload reservation followed by an out-of-bounds write of peer address data.


⚠️ Disclaimer

This repository is intended for authorized security research, kernel vulnerability analysis, CTF environments, kernel debugging, and defensive testing only.

Do not use proof-of-concept code against systems without explicit authorization.


📌 Vulnerability Overview

FieldDetails
CVECVE-2026-74469
CodenameDiagSpill
ComponentLinux Kernel
SubsystemSCTP / sock_diag
Affected Filenet/sctp/associola.c
Primary Functionsctp_assoc_add_peer()
Bug ClassInteger overflow / Out-of-bounds write
ImpactKernel memory corruption
Potential ImpactLocal privilege escalation
CVSS v3.17.0 — High
Attack VectorLocal
Attack ComplexityHigh
Privileges RequiredLow
User InteractionNone
StatusPatched

The Linux Kernel CVE advisory describes the issue as a 16-bit transport_count overflow in SCTP, followed by an undersized INET_DIAG_PEERS allocation and an out-of-bounds write during diagnostic dumping.


🧬 Vulnerability Description

The vulnerable code maintains the number of unique peer transports in a 16-bit counter:

transport_count

Every newly added unique peer increments the counter.

The critical boundary is:

65535

Adding another unique transport causes:

65535 + 1
     ↓
     0

The resulting wraparound creates an inconsistency between:

transport_count

and:

transport_addr_list

The diagnostic subsystem later trusts the wrapped counter when calculating the size of the response buffer, while still iterating through the complete list of peer addresses.


🔬 Root Cause

The vulnerability can be represented as:

                    SCTP Association
                           │
                           ▼
                 Add unique peers
                           │
                           ▼
                 transport_count
                    uint16_t
                           │
                           ▼
                    65,535 peers
                           │
                           ▼
                 + 1 unique peer
                           │
                           ▼
                    Integer wrap
                           │
                           ▼
                transport_count = 0
                           │
                           ▼
                  SCTP sock_diag
                           │
                           ▼
             Reserve incorrect payload
                           │
                           ▼
          Iterate complete peer list
                           │
                           ▼
             Out-of-bounds skb write

The upstream advisory specifically states that the 65,536th transport wraps the counter to zero.


🧠 Why the Bug Happens

The diagnostic code effectively relies on two different views of the same state.

Allocation side

transport_count
       │
       ▼
payload size

Copy side

transport_addr_list
       │
       ▼
copy every peer address

After the integer wraps:

transport_count = 0

transport_addr_list =
    [peer 1]
    [peer 2]
    [peer 3]
    ...
    [peer 65536]

The allocator therefore reserves space based on:

0 peers

while the copy operation can still process:

65536 peer addresses

This mismatch produces the memory-safety violation.


💥 Memory Corruption

The Linux Kernel advisory describes the resulting diagnostic dump as reserving an empty payload and then writing approximately 8 MiB of peer addresses past the skb tail.

Conceptually:

Expected skb:

┌───────────────────────────────┐
│ INET_DIAG header              │
├───────────────────────────────┤
│ Peer addresses                │
└───────────────────────────────┘
              ▲
              │
          valid end


Actual vulnerable state:

┌───────────────────────────────┐
│ INET_DIAG header              │
└───────────────────────────────┘
              ▲
              │
          skb tail

              ↓
      Peer address writes
              ↓
      Peer address writes
              ↓
      Peer address writes
              ↓
      OUT-OF-BOUNDS WRITE

Red Hat classifies the flaw as CWE-787: Out-of-bounds Write.


🔎 Vulnerable Code Path

The relevant path can be summarized as:

SCTP association
      │
      ▼
sctp_assoc_add_peer()
      │
      ▼
transport_count++
      │
      ▼
16-bit overflow
      │
      ▼
SCTP sock_diag
      │
      ▼
INET_DIAG_PEERS
      │
      ▼
skb payload reservation
      │
      ▼
transport_addr_list iteration
      │
      ▼
Out-of-bounds write

The affected source file is:

net/sctp/associola.c

The Linux Kernel CVE announcement identifies this file explicitly.


🩹 Upstream Fix

The upstream fix is:

bd0e9289e2642f6a5c54faad304ce0f41e926d22

Commit:

sctp: prevent peer transport count overflow

The fix rejects a new unique peer when:

transport_count >= U16_MAX

Importantly, the check occurs after the existing-peer lookup.

That preserves the ability to retrieve an already-existing transport even when the association has reached the limit.


🛡️ Patch Logic

Vulnerable

New peer
   │
   ▼
transport_count++
   │
   ▼
Possible 16-bit wrap
   │
   ▼
Diagnostic size mismatch
   │
   ▼
OOB write

Patched

New peer
   │
   ▼
Existing peer?
   │
 ┌─┴──────────┐
 │            │
YES           NO
 │            │
 ▼            ▼
Reuse       Check U16_MAX
transport       │
                ▼
          Reject at limit

The important security property is preventing the counter from ever wrapping while preserving normal lookup semantics for an existing peer.


📊 Vulnerable vs Patched

टूल डाउनलोड करें