CVE-2026-68296

Source
https://cve.org/CVERecord?id=CVE-2026-68296
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68296.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68296
Downstream
Published
2026-08-10T12:02:29.464Z
Modified
2026-08-12T04:18:47.495601716Z
Summary
net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
Details

In the Linux kernel, the following vulnerability has been resolved:

net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM

Before commit 00d066a4d4ed ("netdevfeatures: convert NETIFFLLTX to dev->lltx"), NETIFF_LLTX was set unconditionally in both __gretunnelinit() and ip6gretnlinitfeatures() alongside GREFEATURES:

dev->features |= GRE_FEATURES | NETIF_F_LLTX;

When that commit converted NETIFFLLTX to the dev->lltx flag, it placed 'dev->lltx = true' after the SEQ/CSUM early returns instead of before them. This causes GRE/GRETAP/ip6gre tunnels with SEQ or CSUM+encap to lose lockless TX, reintroducing xmitlock acquisition around their ndostartxmit. Since GRE xmit re-enters the stack via iptunnelxmit(), holding xmitlock risks ABBA deadlock with the underlay device.

CPU0 CPU1 ---- ---- lock(&qdiscxmitlockkey#6); lock(&qdiscxmitlockkey#3); lock(&qdiscxmitlockkey#6); lock(&qdiscxmitlockkey#3);

Fix by moving dev->lltx = true before the early returns in both functions, restoring the original unconditional behavior.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68296.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
00d066a4d4edbe559ba6c35153da71d4b2b8a383
Fixed
9f948e9aede9678f4103457daf2bc9dd54c65a06
Fixed
15a1c5f2ed2eeb3daad8d5766fd506aeda4710f3
Fixed
2bffe379023512d280337c70faeb6a8cc435db5e
Fixed
675ed582c1aa4d919dd535490de08c015005c653

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68296.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.12.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68296.json"