CRITICAL Introduced in 2.6.24
sctp AuthChunk Bypass
CVE-2026-68300
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI9.1CRITICAL
01Description
In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. skb_clone() failed in the BH receive path, leaving auth_chunk NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new connections, so the early sctp_auth_recv_cid() check cannot catch this. 2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never called and auth_chunk remains NULL. Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL: if authentication is required, return false to drop the chunk; otherwise continue normally.
02KernelScan AI Analysis
Risk summary
An unauthenticated remote attacker can bypass SCTP AUTH chunk verification by sending a COOKIE-ECHO without a preceding AUTH chunk, or by triggering an skb_clone failure in the receive path. This allows the attacker to inject unauthenticated SCTP chunks, potentially leading to unauthorized connection establishment or data injection.
Vulnerability analysis
When an SCTP endpoint receives certain chunks, the kernel incorrectly skips the authentication check if the authentication chunk is missing. This happens during new connection setup when the required authentication chunk is absent, or when a low-memory condition prevents the receive path from preparing the chunk data. The corrected code now checks whether the incoming chunk type actually requires authentication before accepting it, dropping the packet if authentication is mandatory but missing. Any remote attacker who can send SCTP traffic to a listening endpoint can trigger this bypass.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 2.6.24 | 5.10.265 | a129792b3aef |
| 5.15 | 2.6.24 | 5.15.216 | 5a022ac51ad8 |
| 6.1 | 2.6.24 | 6.1.183 | 6caf0e8590c0 |
| 6.18 | 2.6.24 | 6.18.42 | 18957373920c |
| 6.12 | 2.6.24 | 6.12.101 | 28c5fdce9dd9 |
| 7.1 | 2.6.24 | 7.1.6 | 83f5031f2a6a |
| mainline | 2.6.24 | 7.2 | 8e04823c120b |
| 6.6 | 2.6.24 | 6.6.148 | ec2e157fc967 |