CVE-2026-68320
Last modified
CVE-2026-68320 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid sctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the capacity limit for ep->auth_chunk_list, allowing it to hold up to 20 chunk entries (param_hdr.length up to 24). However, the copy destination asoc->c.auth_chunks in struct sctp_cookie is only SCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes).
Description
In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid sctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the capacity limit for ep->auth_chunk_list, allowing it to hold up to 20 chunk entries (param_hdr.length up to 24). However, the copy destination asoc->c.auth_chunks in struct sctp_cookie is only SCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16 chunks are added, sctp_association_init() memcpy overflows the destination by up to 4 bytes. Fix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching the destination capacity.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 1f485649f52929d9937b346a920a522a7363e202, < 5a365f1e423444c5da7eb689a8661633dad43e48; >= 1f485649f52929d9937b346a920a522a7363e202, < 886e28e14ab655012779016d251fef53d103aa12; >= 1f485649f52929d9937b346a920a522a7363e202, < 11092d79eb2b7c0068382f72fc2416d1786bb2e0; >= 1f485649f52929d9937b346a920a522a7363e202, < b6ea3dda09eb4d5caf7bbc00f857688cf9e98255; >= 1f485649f52929d9937b346a920a522a7363e202, < ff04b26794a16a8a879eb4fd2c02c2d6b03850e9 |
| Linux | Linux | 2.6.24 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68320?
How severe is CVE-2026-68320?
How do I fix CVE-2026-68320?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68315In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68316In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68317In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68318In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68319In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6832Hermes WebUI contains an arbitrary file deletion vulnerabili…8.1
- CVE-2026-68321In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68322In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68323In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68324In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68325In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68326In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-68320?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
