CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
In the Linux kernel, the following vulnerability has been resolved:
sctp: fix authchunklist capacity check in sctpauthepaddchunkid
sctpauthepaddchunkid() uses SCTPNUMCHUNKTYPES (20) as the capacity limit for ep->authchunklist, allowing it to hold up to 20 chunk entries (paramhdr.length up to 24). However, the copy destination asoc->c.authchunks in struct sctpcookie is only SCTPAUTHMAXCHUNKS (16) entries (20 bytes). When more than 16 chunks are added, sctpassociationinit() memcpy overflows the destination by up to 4 bytes.
Fix by using SCTPAUTHMAXCHUNKS as the capacity limit, matching the destination capacity.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernel (sctp)to a version that resolves this vulnerability.Patch sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid - Configuration
Update sctp_auth_ep_add_chunkid() so the memcpy destination capacity check uses SCTP_AUTH_MAX_CHUNKS (16), preventing overflow when ep->auth_chunk_list holds up to SCTP_AUTH_MAX_CHUNKS entries (rather than using SCTP_NUM_CHUNK_TYPES (20)).
Linux kernel (sctp auth) capacity limit (ep->auth_chunk_list / asoc->c.auth_chunks) = Use SCTP_AUTH_MAX_CHUNKS (16) as capacity limit (not SCTP_NUM_CHUNK_TYPES (20))
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68320?
CVE-2026-68320 has a risk rating of 42.
How do I fix CVE-2026-68320?
To fix CVE-2026-68320, ensure that you update to the patched version of the Linux kernel where the vulnerability has been resolved.
What systems are affected by CVE-2026-68320?
CVE-2026-68320 affects systems running vulnerable versions of the Linux kernel that utilize SCTP.
What are the potential impacts of CVE-2026-68320?
Exploitation of CVE-2026-68320 could lead to denial of service or unauthorized access to system resources.
When was CVE-2026-68320 published?
CVE-2026-68320 was published on August 10, 2026.