{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-68136","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-30T09:28:09.370Z","datePublished":"2026-08-10T11:58:59.450Z","dateUpdated":"2026-08-23T12:45:54.689Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-23T12:45:54.689Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gro: fix double aggregation of flush-marked skbs\n\nCommit 0ab03f353d36 (\"net-gro: Fix GRO flush when receiving a GSO\npacket.\") added a flush check to skb_gro_receive(), but\nskb_gro_receive_list() lacks the same validation.\n\nAs a result, packets marked with NAPI_GRO_CB(skb)->flush may still be\nre-aggregated.\n\nThis allows already-GRO'd packets with existing frag_list to be\nre-aggregated into a new GRO session, corrupting the frag_list chain\nstructure. When skb_segment() attempts to unpack these malformed packets,\nit encounters invalid state and triggers a kernel panic.\n\nScenario (Tethering/Device forwarding):\n  1. Driver: Generated aggregated packet P1 via LRO with frag_list\n  2. Dev A: Receives aggregated fraglist packet and flush flag set\n  3. Dev A: Re-enters GRO, skb_gro_receive_list() is called\n  4. Missing flush check allows re-aggregation despite flush flag\n  5. Frag_list chain becomes corrupted (loops or dangling refs)\n  6. Dev B: TX path calls skb_segment(), crashes on corrupted frag_list\n\nRoot cause in skb_segment():\n  The check at line ~4891:\n    if (hsize <= 0 && i >= nfrags && skb_headlen(list_skb) &&\n        (skb_headlen(list_skb) == len || sg)) {\n\n  When frag_list is corrupted by double aggregation, when list_skb is\n  a NULL pointer from skb->next, skb_headlen(list_skb) dereference\n  NULL/corrupted pointers occurs.\n\nCall Trace:\n skb_headlen(NULL skb)\n skb_segment\n tcp_gso_segment\n tcp4_gso_segment\n inet_gso_segment\n skb_mac_gso_segment\n __skb_gso_segment\n skb_gso_segment\n validate_xmit_skb\n validate_xmit_skb_list\n sch_direct_xmit\n qdisc_restart\n __qdisc_run\n qdisc_run\n net_tx_action\n\nFix: Add NAPI_GRO_CB(skb)->flush validation to the early-return check in\nskb_gro_receive_list(), matching the defensive programming pattern of\nskb_gro_receive()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The bug is reached from the standard NAPI GRO receive path processing remotely originated TCP/IP packets (napi_gro_receive→dev_gro_receive→tcp_gro_receive→skb_gro_receive_list), including tethering/NAT/forwarding scenarios where packets re-enter GRO on a second netdev after driver LRO or prior GRO aggregation.\nAC:L - An attacker can reliably trigger the bug by crafting a TCP stream through a forwarding host with rx-gro-list enabled, without races or victim-specific timing; the commit documents a deterministic tethering/forwarding repro where flush-marked frag_list skbs are re-aggregated and later crash skb_segment.\nPR:N - No local privileges or authentication are required; any remote peer that can send TCP traffic through a vulnerable forwarding/tethering/NAT Linux host can reach the GRO fraglist merge path, which performs no capability or credential checks on the receive path.\nUI:N - Exploitation requires only network-delivered packets and normal kernel forwarding/GRO processing; the victim does not need to open files, mount filesystems, click links, or perform any deliberate action beyond routine network operation.\nS:U - Impact is confined to kernel memory corruption and panic within the same host kernel security domain during packet GRO aggregation and subsequent segmentation on transmit; it does not cross VM, container, or IOMMU boundaries to affect a separate security authority.\nC:H - Double aggregation corrupts the skb frag_list chain (loops, dangling references, NULL/corrupted list_skb pointers), constituting kernel heap memory corruption that can be read during skb_segment processing and is classifiable as a high-impact info-disclosure primitive beyond a simple crash.\nI:H - Re-aggregating flush-marked skbs with existing frag_list corrupts skb linked-list structure and reference relationships in kernel memory, enabling potential control of subsequent skb metadata and write/control-flow primitives during GSO segmentation, not merely integrity-preserving packet drops.\nA:H - Corrupted frag_list state causes skb_segment to dereference a NULL or invalid list_skb via skb_headlen(), producing a kernel panic/oops on the transmit path (sch_direct_xmit/qdisc_run), fully denying availability of the affected system."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/gro.c"],"versions":[{"version":"3a1296a38d0cf62bffb9a03c585cbd5dbf15d596","lessThan":"7fc7e35212cf58c134310fb47566a844297ceae9","status":"affected","versionType":"git"},{"version":"3a1296a38d0cf62bffb9a03c585cbd5dbf15d596","lessThan":"d1fb23f8f794ac4683127bd49a6422bd87e0ac02","status":"affected","versionType":"git"},{"version":"3a1296a38d0cf62bffb9a03c585cbd5dbf15d596","lessThan":"db3e82da616f52e2b27e25e7be3fde2f2a5e54d6","status":"affected","versionType":"git"},{"version":"3a1296a38d0cf62bffb9a03c585cbd5dbf15d596","lessThan":"107e1a469f53a2a70874f3f12bf6fcd23925da1d","status":"affected","versionType":"git"},{"version":"3a1296a38d0cf62bffb9a03c585cbd5dbf15d596","lessThan":"a4dfd46cc8f08a29c6183794790547d0945f3d45","status":"affected","versionType":"git"},{"version":"3a1296a38d0cf62bffb9a03c585cbd5dbf15d596","lessThan":"fc0c0f7a207f0cd2d2aa725696c907f7d03af9e0","status":"affected","versionType":"git"},{"version":"3a1296a38d0cf62bffb9a03c585cbd5dbf15d596","lessThan":"e751256486d0ded20f5a9f9863467f1dce65142f","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/gro.c"],"versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","status":"unaffected","versionType":"semver"},{"version":"5.10.266","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"5.10.266"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.1.184"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.6.153"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.12.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.18.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"7.1.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/7fc7e35212cf58c134310fb47566a844297ceae9"},{"url":"https://git.kernel.org/stable/c/d1fb23f8f794ac4683127bd49a6422bd87e0ac02"},{"url":"https://git.kernel.org/stable/c/db3e82da616f52e2b27e25e7be3fde2f2a5e54d6"},{"url":"https://git.kernel.org/stable/c/107e1a469f53a2a70874f3f12bf6fcd23925da1d"},{"url":"https://git.kernel.org/stable/c/a4dfd46cc8f08a29c6183794790547d0945f3d45"},{"url":"https://git.kernel.org/stable/c/fc0c0f7a207f0cd2d2aa725696c907f7d03af9e0"},{"url":"https://git.kernel.org/stable/c/e751256486d0ded20f5a9f9863467f1dce65142f"}],"title":"net: gro: fix double aggregation of flush-marked skbs","x_generator":{"engine":"bippy-1.2.0"}}}}