KernelScan.io

HIGH Introduced in 2.6.24

sctp AuthChunkList Overflow

CVE-2026-68320

CVSS 7.3 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

KernelScan AI7.8HIGH

01

In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid sctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the capacity limit for ep->auth_chunk_list, allowing it to hold up to 20 chunk entries (param_hdr.length up to 24). However, the copy destination asoc->c.auth_chunks in struct sctp_cookie is only SCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16 chunks are added, sctp_association_init() memcpy overflows the destination by up to 4 bytes. Fix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching the destination capacity.

02

Engine v0.6.0

Risk summary

A local unprivileged user can overflow a kernel heap buffer by configuring an SCTP endpoint with more authentication chunk types than the association cookie can hold. When an association is established, the kernel copies the oversized list into the undersized cookie buffer, corrupting adjacent heap memory. This can lead to kernel code execution, privilege escalation, or a system crash.

Affectednet/sctp/auth.c (sctp auth)

Vulnerability analysis

The SCTP authentication subsystem permits an endpoint's auth chunk list to grow to 20 entries, but the association cookie structure that receives a copy of that list during association initialization only has room for 16 entries. When more than 16 chunk types have been configured and an association is formed, the kernel's copy operation writes up to four bytes past the end of the cookie buffer, corrupting adjacent heap memory. The fix changes the capacity check to limit the chunk list to 16 entries, matching the destination buffer size and preventing the overflow. Any local user who can create an SCTP socket and set authentication options via setsockopt can trigger this; no special privileges are required, and the association can be established over loopback.

03

BranchIntroducedFixed inPatch commit
5.102.6.245.10.2653d22a7da2e26
5.152.6.245.15.2166837c1c19a25
6.12.6.246.1.18354bb4c03fa17
6.62.6.246.6.1485a365f1e4234
6.182.6.246.18.4211092d79eb2b
7.12.6.247.1.6b6ea3dda09eb
mainline2.6.247.2ff04b26794a1
6.122.6.246.12.101886e28e14ab6