Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-74469 — Research repository for CVE-2026-74469 (DiagSpill), a Linux kernel SCTP peer transport counter overflow causing an out-of-bounds write, with PoC, root-cause analysis, and patch details. | Kitploit
도구/GitHubGitHub/0xblackash/cve-2026-74469
Privilege EscalationMemory ForensicsVulnerability AnalysisExploitationPapers & ResearchLearning & EducationBinary ExploitationLabs & Practice
GitHub0xblackash/cve-2026-74469

CVE-2026-74469

Research repository for CVE-2026-74469 (DiagSpill), a Linux kernel SCTP peer transport counter overflow causing an out-of-bounds write, with PoC, root-cause analysis, and patch details.

16811일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

⚡ CVE-2026-74469 — DiagSpill

Gemini_Generated_Image_yv49p8yv49p8yv49

Linux Kernel SCTP Peer Transport Count Overflow

A Linux kernel SCTP vulnerability caused by a 16-bit peer transport counter overflow, allowing the counter to wrap from 65535 to 0. During an SCTP diagnostic dump, the wrapped value can cause insufficient skb payload reservation followed by an out-of-bounds write of peer address data.


⚠️ Disclaimer

This repository is intended for authorized security research, kernel vulnerability analysis, CTF environments, kernel debugging, and defensive testing only.

Do not use proof-of-concept code against systems without explicit authorization.


📌 Vulnerability Overview

FieldDetails
CVECVE-2026-74469
CodenameDiagSpill
ComponentLinux Kernel
SubsystemSCTP / sock_diag
Affected Filenet/sctp/associola.c
Primary Functionsctp_assoc_add_peer()
Bug ClassInteger overflow / Out-of-bounds write
ImpactKernel memory corruption
Potential ImpactLocal privilege escalation
CVSS v3.17.0 — High
Attack VectorLocal
Attack ComplexityHigh
Privileges RequiredLow
User InteractionNone
StatusPatched

The Linux Kernel CVE advisory describes the issue as a 16-bit transport_count overflow in SCTP, followed by an undersized INET_DIAG_PEERS allocation and an out-of-bounds write during diagnostic dumping.


🧬 Vulnerability Description

The vulnerable code maintains the number of unique peer transports in a 16-bit counter:

transport_count

Every newly added unique peer increments the counter.

The critical boundary is:

65535

Adding another unique transport causes:

65535 + 1
     ↓
     0

The resulting wraparound creates an inconsistency between:

transport_count

and:

transport_addr_list

The diagnostic subsystem later trusts the wrapped counter when calculating the size of the response buffer, while still iterating through the complete list of peer addresses.


🔬 Root Cause

The vulnerability can be represented as:

                    SCTP Association
                           │
                           ▼
                 Add unique peers
                           │
                           ▼
                 transport_count
                    uint16_t
                           │
                           ▼
                    65,535 peers
                           │
                           ▼
                 + 1 unique peer
                           │
                           ▼
                    Integer wrap
                           │
                           ▼
                transport_count = 0
                           │
                           ▼
                  SCTP sock_diag
                           │
                           ▼
             Reserve incorrect payload
                           │
                           ▼
          Iterate complete peer list
                           │
                           ▼
             Out-of-bounds skb write

The upstream advisory specifically states that the 65,536th transport wraps the counter to zero.


🧠 Why the Bug Happens

The diagnostic code effectively relies on two different views of the same state.

Allocation side

transport_count
       │
       ▼
payload size

Copy side

transport_addr_list
       │
       ▼
copy every peer address

After the integer wraps:

transport_count = 0

transport_addr_list =
    [peer 1]
    [peer 2]
    [peer 3]
    ...
    [peer 65536]

The allocator therefore reserves space based on:

0 peers

while the copy operation can still process:

65536 peer addresses

This mismatch produces the memory-safety violation.


💥 Memory Corruption

The Linux Kernel advisory describes the resulting diagnostic dump as reserving an empty payload and then writing approximately 8 MiB of peer addresses past the skb tail.

Conceptually:

Expected skb:

┌───────────────────────────────┐
│ INET_DIAG header              │
├───────────────────────────────┤
│ Peer addresses                │
└───────────────────────────────┘
              ▲
              │
          valid end


Actual vulnerable state:

┌───────────────────────────────┐
│ INET_DIAG header              │
└───────────────────────────────┘
              ▲
              │
          skb tail

              ↓
      Peer address writes
              ↓
      Peer address writes
              ↓
      Peer address writes
              ↓
      OUT-OF-BOUNDS WRITE

Red Hat classifies the flaw as CWE-787: Out-of-bounds Write.


🔎 Vulnerable Code Path

The relevant path can be summarized as:

SCTP association
      │
      ▼
sctp_assoc_add_peer()
      │
      ▼
transport_count++
      │
      ▼
16-bit overflow
      │
      ▼
SCTP sock_diag
      │
      ▼
INET_DIAG_PEERS
      │
      ▼
skb payload reservation
      │
      ▼
transport_addr_list iteration
      │
      ▼
Out-of-bounds write

The affected source file is:

net/sctp/associola.c

The Linux Kernel CVE announcement identifies this file explicitly.


🩹 Upstream Fix

The upstream fix is:

bd0e9289e2642f6a5c54faad304ce0f41e926d22

Commit:

sctp: prevent peer transport count overflow

The fix rejects a new unique peer when:

transport_count >= U16_MAX

Importantly, the check occurs after the existing-peer lookup.

That preserves the ability to retrieve an already-existing transport even when the association has reached the limit.


🛡️ Patch Logic

Vulnerable

New peer
   │
   ▼
transport_count++
   │
   ▼
Possible 16-bit wrap
   │
   ▼
Diagnostic size mismatch
   │
   ▼
OOB write

Patched

New peer
   │
   ▼
Existing peer?
   │
 ┌─┴──────────┐
 │            │
YES           NO
 │            │
 ▼            ▼
Reuse       Check U16_MAX
transport       │
                ▼
          Reject at limit

The important security property is preventing the counter from ever wrapping while preserving normal lookup semantics for an existing peer.


📊 Vulnerable vs Patched

도구 다운로드