{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-68288","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-30T09:28:09.380Z","datePublished":"2026-08-10T12:02:21.097Z","dateUpdated":"2026-10-03T10:55:44.026Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:55:44.026Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD\n\nnet_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code\nthe NET_DM_ATTR_PAYLOAD attribute to avoid zeroing the packet payload\nbefore overwriting it with skb_copy_bits().\n\nskb_put() reserves nla_total_size(payload_len), i.e. the header plus the\nNLA_ALIGN() padding, but only payload_len bytes are copied in. When\npayload_len is not a multiple of 4 the 1-3 padding bytes are never\ninitialized and are leaked to user space inside the netlink message.\n\nKMSAN confirms the leak for the software path when the packet payload\nlength is not 4-byte aligned:\n\n  BUG: KMSAN: kernel-infoleak in _copy_to_iter\n   _copy_to_iter\n   __skb_datagram_iter\n   skb_copy_datagram_iter\n   netlink_recvmsg\n   sock_recvmsg\n   __sys_recvfrom\n  Uninit was created at:\n   kmem_cache_alloc_node_noprof\n   __alloc_skb\n   net_dm_packet_work\n  Bytes 173-175 of 176 are uninitialized\n\nUse __nla_reserve(), which sets up the attribute header and zeroes the\npadding, instead of open coding the attribute construction."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/drop_monitor.c"],"versions":[{"version":"ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f","lessThan":"d427b152b663cb2b19fcd449d792e17edbe4a938","status":"affected","versionType":"git"},{"version":"ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f","lessThan":"3c0bc7dcc5f9257d25c59eeb7ccb4df33dcfc446","status":"affected","versionType":"git"},{"version":"ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f","lessThan":"05173de42a9923a3eaadebcb0dd5bc83ffba174c","status":"affected","versionType":"git"},{"version":"ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f","lessThan":"89178ffe5bddc99c057ba2768db1f8d9c5e1408c","status":"affected","versionType":"git"},{"version":"ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f","lessThan":"8fd6975d2aecc36b25ee82b6aef88e62a3527ccb","status":"affected","versionType":"git"},{"version":"ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f","lessThan":"5e9c8baee0329fbefe7c67aea945e2a07f15e98b","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/drop_monitor.c"],"versions":[{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"7.1.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d427b152b663cb2b19fcd449d792e17edbe4a938"},{"url":"https://git.kernel.org/stable/c/3c0bc7dcc5f9257d25c59eeb7ccb4df33dcfc446"},{"url":"https://git.kernel.org/stable/c/05173de42a9923a3eaadebcb0dd5bc83ffba174c"},{"url":"https://git.kernel.org/stable/c/89178ffe5bddc99c057ba2768db1f8d9c5e1408c"},{"url":"https://git.kernel.org/stable/c/8fd6975d2aecc36b25ee82b6aef88e62a3527ccb"},{"url":"https://git.kernel.org/stable/c/5e9c8baee0329fbefe7c67aea945e2a07f15e98b"}],"title":"net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD","x_generator":{"engine":"bippy-1.2.0"}}}}