CVE-2026-68338

Source
https://cve.org/CVERecord?id=CVE-2026-68338
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68338.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68338
Downstream
Published
2026-08-10T12:03:14.549Z
Modified
2026-08-18T03:31:14.741478125Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net/packet: avoid fanout hook re-registration after unregister
Details

In the Linux kernel, the following vulnerability has been resolved:

net/packet: avoid fanout hook re-registration after unregister

packetsetring() temporarily detaches a socket from packet delivery while reconfiguring its ring. It records the previous running state, clears po->num, unregisters the protocol hook when needed, drops po->bindlock, and later restores po->num and re-registers the hook from the saved wasrunning value.

That unlocked window can race with NETDEV_UNREGISTER. The notifier can observe the socket as not running, skip __unregisterprothook(), and invalidate the per-socket binding by setting po->ifindex to -1 and clearing po->prothook.dev. A one-member fanout group can still retain its shared fanout hook device pointer. When packetsetring() resumes, re-registering solely from the stale wasrunning state can re-add the fanout hook after the device has been unregistered.

Treat po->ifindex == -1 as an invalidated binding after reacquiring po->bind_lock. This is distinct from ifindex 0, the normal unbound/wildcard state: ifindex -1 marks an existing device binding that was invalidated when the device was unregistered. Restore po->num as before, but do not re-register the hook if device unregister already detached the socket.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68338.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
dc99f600698dcac69b8f56dda9a8a00d645c5ffc
Fixed
80ec024d53a05c60ad1d08968dcf745f10c1665c
Fixed
0a052e0808e015e68144a9877e6ef42b952c49fa
Fixed
1bc55c29cd85818e9052f17deb287d5a11fb817f
Fixed
a885387dae7986a55bae5c77a15bdd447f64e9b9
Fixed
50aff80475abd3533eef4320477037e6fcc6b56e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68338.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.1.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68338.json"