7.3

CVE-2026-68320

sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid

In the Linux kernel, the following vulnerability has been resolved:

sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid

sctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the
capacity limit for ep->auth_chunk_list, allowing it to hold up to
20 chunk entries (param_hdr.length up to 24). However, the copy
destination asoc->c.auth_chunks in struct sctp_cookie is only
SCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16
chunks are added, sctp_association_init() memcpy overflows the
destination by up to 4 bytes.

Fix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching
the destination capacity.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1f485649f52929d9937b346a920a522a7363e202
Version < 3d22a7da2e264f407c729f33a0a346ff76108bc6
Status affected
Version 1f485649f52929d9937b346a920a522a7363e202
Version < 6837c1c19a259518974cbc5a52017646e3906564
Status affected
Version 1f485649f52929d9937b346a920a522a7363e202
Version < 54bb4c03fa17cdcb157c26c33e60a78cf32960f5
Status affected
Version 1f485649f52929d9937b346a920a522a7363e202
Version < 5a365f1e423444c5da7eb689a8661633dad43e48
Status affected
Version 1f485649f52929d9937b346a920a522a7363e202
Version < 886e28e14ab655012779016d251fef53d103aa12
Status affected
Version 1f485649f52929d9937b346a920a522a7363e202
Version < 11092d79eb2b7c0068382f72fc2416d1786bb2e0
Status affected
Version 1f485649f52929d9937b346a920a522a7363e202
Version < b6ea3dda09eb4d5caf7bbc00f857688cf9e98255
Status affected
Version 1f485649f52929d9937b346a920a522a7363e202
Version < ff04b26794a16a8a879eb4fd2c02c2d6b03850e9
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.24
Status affected
Version 0
Version < 2.6.24
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.028
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.3 1.8 5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5a365f1e423444c5da7eb689a8661633dad43e48
https://git.kernel.org/stable/c/886e28e14ab655012779016d251fef53d103aa12
https://git.kernel.org/stable/c/11092d79eb2b7c0068382f72fc2416d1786bb2e0
https://git.kernel.org/stable/c/b6ea3dda09eb4d5caf7bbc00f857688cf9e98255
https://git.kernel.org/stable/c/ff04b26794a16a8a879eb4fd2c02c2d6b03850e9
https://git.kernel.org/stable/c/3d22a7da2e264f407c729f33a0a346ff76108bc6
https://git.kernel.org/stable/c/54bb4c03fa17cdcb157c26c33e60a78cf32960f5
https://git.kernel.org/stable/c/6837c1c19a259518974cbc5a52017646e3906564