Bug 2513474 (CVE-2026-68315)
| Summary: | CVE-2026-68315 kernel: sctp: validate stream count in sctp_process_strreset_inreq() | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation. When processing a Stream Reset Incoming Request (RESET_IN_REQUEST) from a peer, the kernel does not properly validate the stream count. This can lead to an integer overflow when calculating the size for the corresponding outgoing request, resulting in an undersized memory allocation. A remote attacker could exploit this vulnerability on interfaces supporting large Maximum Transmission Units (MTU) to trigger a kernel bug, causing a denial of service.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-10 12:39:23 UTC
|