CVE-2026-68320

Source
https://cve.org/CVERecord?id=CVE-2026-68320
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68320.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68320
Downstream
Published
2026-08-10T12:02:55Z
Modified
2026-08-21T03:30:45Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H CVSS Calculator
Summary
sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
Details

In the Linux kernel, the following vulnerability has been resolved:

sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid

sctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the capacity limit for ep->auth_chunk_list, allowing it to hold up to 20 chunk entries (param_hdr.length up to 24). However, the copy destination asoc->c.auth_chunks in struct sctp_cookie is only SCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16 chunks are added, sctp_association_init() memcpy overflows the destination by up to 4 bytes.

Fix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching the destination capacity.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68320.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1f485649f52929d9937b346a920a522a7363e202
Fixed
3d22a7da2e264f407c729f33a0a346ff76108bc6
Fixed
6837c1c19a259518974cbc5a52017646e3906564
Fixed
54bb4c03fa17cdcb157c26c33e60a78cf32960f5
Fixed
5a365f1e423444c5da7eb689a8661633dad43e48
Fixed
886e28e14ab655012779016d251fef53d103aa12
Fixed
11092d79eb2b7c0068382f72fc2416d1786bb2e0
Fixed
b6ea3dda09eb4d5caf7bbc00f857688cf9e98255
Fixed
ff04b26794a16a8a879eb4fd2c02c2d6b03850e9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68320.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.24
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68320.json"