In the Linux kernel, the following vulnerability has been resolved:
net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
Before commit 00d066a4d4ed ("netdevfeatures: convert NETIFFLLTX to dev->lltx"), NETIFF_LLTX was set unconditionally in both __gretunnelinit() and ip6gretnlinitfeatures() alongside GREFEATURES:
dev->features |= GRE_FEATURES | NETIF_F_LLTX;
When that commit converted NETIFFLLTX to the dev->lltx flag, it placed 'dev->lltx = true' after the SEQ/CSUM early returns instead of before them. This causes GRE/GRETAP/ip6gre tunnels with SEQ or CSUM+encap to lose lockless TX, reintroducing xmitlock acquisition around their ndostartxmit. Since GRE xmit re-enters the stack via iptunnelxmit(), holding xmitlock risks ABBA deadlock with the underlay device.
CPU0 CPU1 ---- ---- lock(&qdiscxmitlockkey#6); lock(&qdiscxmitlockkey#3); lock(&qdiscxmitlockkey#6); lock(&qdiscxmitlockkey#3);
Fix by moving dev->lltx = true before the early returns in both functions, restoring the original unconditional behavior.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68296.json",
"cna_assigner": "Linux"
}