CVE-2026-68315
sctp: validate stream count in sctp_process_strreset_inreq()
Description
In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check whether the resulting RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN. The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes larger than the IN request header (sctp_strreset_inreq, 8 bytes). Generally, the IP payload is bounded to 65535 bytes, so the stream list cannot be large enough to trigger the overflow. However, on interfaces with MTU > 65535 (e.g., loopback with IPv6 jumbograms), a stream list that fits within the incoming IN parameter can cause a __u16 overflow in sctp_make_strreset_req() when computing the OUT request size, leading to an undersized skb allocation and a kernel BUG: net/core/skbuff.c:207 skb_panic net/core/skbuff.c:2625 skb_put net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req net/sctp/stream.c:655 sctp_process_strreset_inreq The local setsockopt path validates the generated reset request size. However, for an incoming-only reset, it accounts for the smaller IN request even though the peer must generate an OUT request with the same stream list. Such a request cannot be completed successfully by the peer. Reject peer IN requests whose corresponding OUT request would exceed SCTP_MAX_CHUNK_LEN. Also tighten the local check so it does not send an IN request that would require an oversized OUT request from the peer.
INFO
Published Date :
Aug. 10, 2026, 1:20 p.m.
Last Modified :
Aug. 17, 2026, 5:18 a.m.
Remotely Exploit :
Yes !
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Update the Linux kernel to a patched version.
- Reject incoming requests exceeding maximum chunk length.
- Tighten local checks for outgoing request sizes.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-68315.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-68315 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-68315
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-68315 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-68315 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 17, 2026
Action Type Old Value New Value Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': 'b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '6f0e39d180cd7cced647381b6fa14fd83d261047', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '1a10fe1aa9c01f41b389a31906a77d538637c9d9', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '00ae679cb21a035491fdad8d58dc6d79cc68b675', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '18ae07691d43183d270de8be9dc8e027906015d9', 'versionType': 'git'}], 'programFiles': ['net/sctp/stream.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.11'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.11', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc5', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/stream.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': 'b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '6f0e39d180cd7cced647381b6fa14fd83d261047', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '1a10fe1aa9c01f41b389a31906a77d538637c9d9', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '00ae679cb21a035491fdad8d58dc6d79cc68b675', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '18ae07691d43183d270de8be9dc8e027906015d9', 'versionType': 'git'}], 'programFiles': ['net/sctp/stream.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.11'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.11', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/stream.c'], 'defaultStatus': 'affected'}] -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 13, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 10, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': 'b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '6f0e39d180cd7cced647381b6fa14fd83d261047', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '1a10fe1aa9c01f41b389a31906a77d538637c9d9', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '00ae679cb21a035491fdad8d58dc6d79cc68b675', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '18ae07691d43183d270de8be9dc8e027906015d9', 'versionType': 'git'}], 'programFiles': ['net/sctp/stream.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.11'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.11', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc5', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/stream.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check whether the resulting RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN. The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes larger than the IN request header (sctp_strreset_inreq, 8 bytes). Generally, the IP payload is bounded to 65535 bytes, so the stream list cannot be large enough to trigger the overflow. However, on interfaces with MTU > 65535 (e.g., loopback with IPv6 jumbograms), a stream list that fits within the incoming IN parameter can cause a __u16 overflow in sctp_make_strreset_req() when computing the OUT request size, leading to an undersized skb allocation and a kernel BUG: net/core/skbuff.c:207 skb_panic net/core/skbuff.c:2625 skb_put net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req net/sctp/stream.c:655 sctp_process_strreset_inreq The local setsockopt path validates the generated reset request size. However, for an incoming-only reset, it accounts for the smaller IN request even though the peer must generate an OUT request with the same stream list. Such a request cannot be completed successfully by the peer. Reject peer IN requests whose corresponding OUT request would exceed SCTP_MAX_CHUNK_LEN. Also tighten the local check so it does not send an IN request that would require an oversized OUT request from the peer. Added Reference https://git.kernel.org/stable/c/00ae679cb21a035491fdad8d58dc6d79cc68b675 Added Reference https://git.kernel.org/stable/c/18ae07691d43183d270de8be9dc8e027906015d9 Added Reference https://git.kernel.org/stable/c/1a10fe1aa9c01f41b389a31906a77d538637c9d9 Added Reference https://git.kernel.org/stable/c/6f0e39d180cd7cced647381b6fa14fd83d261047 Added Reference https://git.kernel.org/stable/c/b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b