CVE-2026-68320

Source
https://cve.org/CVERecord?id=CVE-2026-68320
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68320.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68320
Downstream
Published
2026-08-10T12:02:55.144Z
Modified
2026-08-12T04:18:47.855554079Z
Summary
sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
Details

In the Linux kernel, the following vulnerability has been resolved:

sctp: fix authchunklist capacity check in sctpauthepaddchunkid

sctpauthepaddchunkid() uses SCTPNUMCHUNKTYPES (20) as the capacity limit for ep->authchunklist, allowing it to hold up to 20 chunk entries (paramhdr.length up to 24). However, the copy destination asoc->c.authchunks in struct sctpcookie is only SCTPAUTHMAXCHUNKS (16) entries (20 bytes). When more than 16 chunks are added, sctpassociation_init() memcpy overflows the destination by up to 4 bytes.

Fix by using SCTPAUTHMAX_CHUNKS as the capacity limit, matching the destination capacity.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68320.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1f485649f52929d9937b346a920a522a7363e202
Fixed
5a365f1e423444c5da7eb689a8661633dad43e48
Fixed
886e28e14ab655012779016d251fef53d103aa12
Fixed
11092d79eb2b7c0068382f72fc2416d1786bb2e0
Fixed
b6ea3dda09eb4d5caf7bbc00f857688cf9e98255
Fixed
ff04b26794a16a8a879eb4fd2c02c2d6b03850e9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68320.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.24
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68320.json"