diff --git a/meta-networking/recipes-support/lksctp-tools/lksctp-tools/0002-func_tests-pass-invalid-msghdr-pointers-straight-to-.patch b/meta-networking/recipes-support/lksctp-tools/lksctp-tools/0002-func_tests-pass-invalid-msghdr-pointers-straight-to-.patch
new file mode 100644
index 0000000000..b73dff2025
--- /dev/null
+++ b/meta-networking/recipes-support/lksctp-tools/lksctp-tools/0002-func_tests-pass-invalid-msghdr-pointers-straight-to-.patch
@@ -0,0 +1,72 @@
+From 5402bce533c3ba8dae022eded7c6ffe7967b7248 Mon Sep 17 00:00:00 2001
+From: Khem Raj <khem.raj@oss.qualcomm.com>
+Date: Sun, 27 Sep 2026 15:52:39 -0700
+Subject: [PATCH 2/3] func_tests: pass invalid msghdr pointers straight to the
+ kernel
+
+test_1_to_1_sendmsg TEST6 and test_1_to_1_recvmsg TEST4 hand
+(struct msghdr *)-1 to sendmsg()/recvmsg() and expect EFAULT from the
+kernel. Passing an invalid pointer to a libc function is undefined, and
+on 64-bit musl both wrappers copy the msghdr first to clear its padding
+fields, so the tests die with SIGSEGV before reaching the syscall.
+
+Use syscall(2) for these two cases so they test what they mean to: the
+kernel's handling of a bad msghdr pointer.
+
+Upstream-Status: Pending
+Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
+---
+ src/func_tests/test_1_to_1_recvmsg.c | 7 ++++++-
+ src/func_tests/test_1_to_1_sendmsg.c | 7 ++++++-
+ 2 files changed, 12 insertions(+), 2 deletions(-)
+
+diff --git a/src/func_tests/test_1_to_1_recvmsg.c b/src/func_tests/test_1_to_1_recvmsg.c
+index 962b7b5..0ccf087 100644
+--- a/src/func_tests/test_1_to_1_recvmsg.c
++++ b/src/func_tests/test_1_to_1_recvmsg.c
+@@ -56,6 +56,7 @@
+ #include <sys/uio.h>
+ #include <linux/socket.h>
+ #include <sctputil.h>
++#include <sys/syscall.h>
+
+ char *TCID = __FILE__;
+ int TST_TOTAL = 8;
+@@ -158,7 +159,11 @@ main(int argc, char *argv[])
+ 	inmessage.msg_iov = &iov_rcv;
+
+ 	/*recvmsg () TEST4: Invalid msghdr pointer EFAULT, Expected error*/
+-	count = recvmsg(acpt_sk, (struct msghdr *)-1, flag);
++	/* Call the kernel directly: libc wrappers may read the msghdr
++	 * themselves (musl copies it to clear padding on 64-bit), which
++	 * crashes instead of returning EFAULT.
++	 */
++	count = syscall(SYS_recvmsg, acpt_sk, (struct msghdr *)-1, flag);
+ 	if (count != -1 || errno != EFAULT)
+ 		tst_brkm(TBROK, tst_exit, "recvmsg with invalid msghdr "
+ 			 "pointer count:%d, errno:%d", count, errno);
+diff --git a/src/func_tests/test_1_to_1_sendmsg.c b/src/func_tests/test_1_to_1_sendmsg.c
+index f2949e7..4f46c78 100644
+--- a/src/func_tests/test_1_to_1_sendmsg.c
++++ b/src/func_tests/test_1_to_1_sendmsg.c
+@@ -63,6 +63,7 @@
+ #include <sys/uio.h>
+ #include <linux/socket.h>
+ #include <sctputil.h>
++#include <sys/syscall.h>
+
+ char *TCID = __FILE__;
+ int TST_TOTAL = 14;
+@@ -200,7 +201,11 @@ main(int argc, char *argv[])
+ 	outmessage.msg_iovlen = 1;
+
+ 	/*sendmsg () TEST6: Invalid msghdr pointer EFAULT, Expected error*/
+-	count = sendmsg(sk, (struct msghdr *)-1, flag);
++	/* Call the kernel directly: libc wrappers may read the msghdr
++	 * themselves (musl copies it to clear padding on 64-bit), which
++	 * crashes instead of returning EFAULT.
++	 */
++	count = syscall(SYS_sendmsg, sk, (struct msghdr *)-1, flag);
+ 	if (count != -1 || errno != EFAULT)
+ 		tst_brkm(TBROK, tst_exit, "sendmsg with invalid msghdr "
+ 			 "pointer count:%d, errno:%d", count, errno);
diff --git a/meta-networking/recipes-support/lksctp-tools/lksctp-tools/0003-connectx-only-export-the-unversioned-sctp_connectx-a.patch b/meta-networking/recipes-support/lksctp-tools/lksctp-tools/0003-connectx-only-export-the-unversioned-sctp_connectx-a.patch
new file mode 100644
index 0000000000..002da14b82
--- /dev/null
+++ b/meta-networking/recipes-support/lksctp-tools/lksctp-tools/0003-connectx-only-export-the-unversioned-sctp_connectx-a.patch
@@ -0,0 +1,49 @@
+From fb2fa4a7af169878f7e7cb2fbf3dba00639d73ed Mon Sep 17 00:00:00 2001
+From: Khem Raj <khem.raj@oss.qualcomm.com>
+Date: Sun, 27 Sep 2026 15:52:39 -0700
+Subject: [PATCH 3/3] connectx: only export the unversioned sctp_connectx alias
+ on glibc
+
+libsctp exports sctp_connectx four times: an unversioned alias of the
+original three-argument API plus the VERS_1, VERS_2 and default VERS_3
+versions. glibc honours the version recorded in the caller, but musl's
+dynamic linker does not implement symbol versioning: it skips the
+hidden VERS_1/VERS_2 entries yet accepts both the unversioned alias and
+sctp_connectx@@VERS_3, and whichever comes first in the hash chain wins.
+That is the unversioned alias, so on musl every sctp_connectx() call
+runs the old API, which ignores the association id argument. The caller
+then reads an uninitialised id, e.g. test_connectx:
+
+  test_connectx.c 3 BROK : Association id mismatch: connectx returned 3,
+  notification returned:240
+
+The alias only exists for binaries linked before libsctp was versioned,
+which is a glibc concern. Emit it only when building against glibc, so
+sctp_connectx@@VERS_3 is the only visible definition elsewhere.
+
+Upstream-Status: Pending
+Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
+---
+ src/lib/connectx.c | 8 ++++++++
+ 1 file changed, 8 insertions(+)
+
+diff --git a/src/lib/connectx.c b/src/lib/connectx.c
+index 2a21e3a..119f6c9 100644
+--- a/src/lib/connectx.c
++++ b/src/lib/connectx.c
+@@ -76,7 +76,15 @@ static int __connectx_addrsize(const struct sockaddr *addrs,
+ }
+
+
++/* The unversioned alias lets glibc resolve references from binaries
++ * built before libsctp had symbol versions. Dynamic linkers without
++ * symbol versioning, such as musl's, pick the first matching name
++ * instead and would bind every sctp_connectx() call to this old API,
++ * which never reports the association id.
++ */
++#ifdef __GLIBC__
+ SYMVER(__sctp_connectx, sctp_connectx@)
++#endif
+ int __sctp_connectx(int fd, struct sockaddr *addrs, int addrcnt)
+ {
+ 	int addrs_size = __connectx_addrsize(addrs, addrcnt);
diff --git a/meta-networking/recipes-support/lksctp-tools/lksctp-tools_1.0.21.bb b/meta-networking/recipes-support/lksctp-tools/lksctp-tools_1.0.21.bb
index f30b7439d5..1f27a04b0c 100644
--- a/meta-networking/recipes-support/lksctp-tools/lksctp-tools_1.0.21.bb
+++ b/meta-networking/recipes-support/lksctp-tools/lksctp-tools_1.0.21.bb
@@ -13,6 +13,8 @@ SRCREV = "37d5f1225573b91d706a5e547d081f79963a9deb"
 SRC_URI = " \
     git://github.com/sctp/lksctp-tools.git;branch=master;protocol=https \
     file://0001-func_tests-disable-FORTIFY_SOURCE-for-test_1_to_1_re.patch \
+    file://0002-func_tests-pass-invalid-msghdr-pointers-straight-to-.patch \
+    file://0003-connectx-only-export-the-unversioned-sctp_connectx-a.patch \
     file://run-ptest \
     file://v4test.sh \
     file://v6test.sh \
