7.5
HIGH CVSS 3.1
CVE-2026-68315
sctp: validate stream count in sctp_process_strreset_inreq()
Description

In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check whether the resulting RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN. The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes larger than the IN request header (sctp_strreset_inreq, 8 bytes). Generally, the IP payload is bounded to 65535 bytes, so the stream list cannot be large enough to trigger the overflow. However, on interfaces with MTU > 65535 (e.g., loopback with IPv6 jumbograms), a stream list that fits within the incoming IN parameter can cause a __u16 overflow in sctp_make_strreset_req() when computing the OUT request size, leading to an undersized skb allocation and a kernel BUG: net/core/skbuff.c:207 skb_panic net/core/skbuff.c:2625 skb_put net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req net/sctp/stream.c:655 sctp_process_strreset_inreq The local setsockopt path validates the generated reset request size. However, for an incoming-only reset, it accounts for the smaller IN request even though the peer must generate an OUT request with the same stream list. Such a request cannot be completed successfully by the peer. Reject peer IN requests whose corresponding OUT request would exceed SCTP_MAX_CHUNK_LEN. Also tighten the local check so it does not send an IN request that would require an oversized OUT request from the peer.

INFO

Published Date :

Aug. 10, 2026, 1:20 p.m.

Last Modified :

Aug. 17, 2026, 5:18 a.m.

Remotely Exploit :

Yes !

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-68315 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
Reject peer requests that exceed the maximum chunk length to prevent kernel bugs.
  • Update the Linux kernel to a patched version.
  • Reject incoming requests exceeding maximum chunk length.
  • Tighten local checks for outgoing request sizes.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-68315 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-68315 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-68315 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-68315 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 17, 2026

    Action Type Old Value New Value
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': 'b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '6f0e39d180cd7cced647381b6fa14fd83d261047', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '1a10fe1aa9c01f41b389a31906a77d538637c9d9', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '00ae679cb21a035491fdad8d58dc6d79cc68b675', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '18ae07691d43183d270de8be9dc8e027906015d9', 'versionType': 'git'}], 'programFiles': ['net/sctp/stream.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.11'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.11', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc5', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/stream.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': 'b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '6f0e39d180cd7cced647381b6fa14fd83d261047', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '1a10fe1aa9c01f41b389a31906a77d538637c9d9', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '00ae679cb21a035491fdad8d58dc6d79cc68b675', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '18ae07691d43183d270de8be9dc8e027906015d9', 'versionType': 'git'}], 'programFiles': ['net/sctp/stream.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.11'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.11', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/stream.c'], 'defaultStatus': 'affected'}]
  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 13, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 10, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': 'b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '6f0e39d180cd7cced647381b6fa14fd83d261047', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '1a10fe1aa9c01f41b389a31906a77d538637c9d9', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '00ae679cb21a035491fdad8d58dc6d79cc68b675', 'versionType': 'git'}, {'status': 'affected', 'version': '7f9d68ac944e24ee5f9ac8d059ca00b1c1d34137', 'lessThan': '18ae07691d43183d270de8be9dc8e027906015d9', 'versionType': 'git'}], 'programFiles': ['net/sctp/stream.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.11'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.11', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc5', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/sctp/stream.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check whether the resulting RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN. The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes larger than the IN request header (sctp_strreset_inreq, 8 bytes). Generally, the IP payload is bounded to 65535 bytes, so the stream list cannot be large enough to trigger the overflow. However, on interfaces with MTU > 65535 (e.g., loopback with IPv6 jumbograms), a stream list that fits within the incoming IN parameter can cause a __u16 overflow in sctp_make_strreset_req() when computing the OUT request size, leading to an undersized skb allocation and a kernel BUG: net/core/skbuff.c:207 skb_panic net/core/skbuff.c:2625 skb_put net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req net/sctp/stream.c:655 sctp_process_strreset_inreq The local setsockopt path validates the generated reset request size. However, for an incoming-only reset, it accounts for the smaller IN request even though the peer must generate an OUT request with the same stream list. Such a request cannot be completed successfully by the peer. Reject peer IN requests whose corresponding OUT request would exceed SCTP_MAX_CHUNK_LEN. Also tighten the local check so it does not send an IN request that would require an oversized OUT request from the peer.
    Added Reference https://git.kernel.org/stable/c/00ae679cb21a035491fdad8d58dc6d79cc68b675
    Added Reference https://git.kernel.org/stable/c/18ae07691d43183d270de8be9dc8e027906015d9
    Added Reference https://git.kernel.org/stable/c/1a10fe1aa9c01f41b389a31906a77d538637c9d9
    Added Reference https://git.kernel.org/stable/c/6f0e39d180cd7cced647381b6fa14fd83d261047
    Added Reference https://git.kernel.org/stable/c/b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.