CVE-2026-68300 PUBLISHED

sctp: auth: verify auth requirement when auth_chunk is NULL

Assigner: Linux
Reserved: 30.07.2026 Published: 10.08.2026 Updated: 10.08.2026

In the Linux kernel, the following vulnerability has been resolved:

sctp: auth: verify auth requirement when auth_chunk is NULL

sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when:

  1. skb_clone() failed in the BH receive path, leaving auth_chunk NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new connections, so the early sctp_auth_recv_cid() check cannot catch this.

  2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never called and auth_chunk remains NULL.

Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL: if authentication is required, return false to drop the chunk; otherwise continue normally.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from bbd0d59809f923ea2b540cbd781b32110e249f6e to ec2e157fc9678a9bc411305a25aec3fd337d7efb (excl.)
  • affected from bbd0d59809f923ea2b540cbd781b32110e249f6e to 28c5fdce9dd955d2baf5e28987819b6d7cfaf646 (excl.)
  • affected from bbd0d59809f923ea2b540cbd781b32110e249f6e to 18957373920caf5cdaf5cf32e5d1d7a99ca7700a (excl.)
  • affected from bbd0d59809f923ea2b540cbd781b32110e249f6e to 83f5031f2a6a49d696eb4cc0898345d12f9c6451 (excl.)
  • affected from bbd0d59809f923ea2b540cbd781b32110e249f6e to 8e04823c120b376ef7dab14b60ebf6823aa16c14 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.24 is affected
  • unaffected from 0 to 2.6.24 (excl.)
  • unaffected from 6.6.148 to 6.6.* (incl.)
  • unaffected from 6.12.101 to 6.12.* (incl.)
  • unaffected from 6.18.42 to 6.18.* (incl.)
  • unaffected from 7.1.6 to 7.1.* (incl.)
  • unaffected from 7.2-rc5 to * (incl.)

References