{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-68136",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-07-30T09:28:09.370Z",
        "datePublished": "2026-08-10T11:58:59.450Z",
        "dateUpdated": "2026-08-23T12:45:54.689Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-23T12:45:54.689Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gro: fix double aggregation of flush-marked skbs\n\nCommit 0ab03f353d36 (\"net-gro: Fix GRO flush when receiving a GSO\npacket.\") added a flush check to skb_gro_receive(), but\nskb_gro_receive_list() lacks the same validation.\n\nAs a result, packets marked with NAPI_GRO_CB(skb)->flush may still be\nre-aggregated.\n\nThis allows already-GRO'd packets with existing frag_list to be\nre-aggregated into a new GRO session, corrupting the frag_list chain\nstructure. When skb_segment() attempts to unpack these malformed packets,\nit encounters invalid state and triggers a kernel panic.\n\nScenario (Tethering/Device forwarding):\n  1. Driver: Generated aggregated packet P1 via LRO with frag_list\n  2. Dev A: Receives aggregated fraglist packet and flush flag set\n  3. Dev A: Re-enters GRO, skb_gro_receive_list() is called\n  4. Missing flush check allows re-aggregation despite flush flag\n  5. Frag_list chain becomes corrupted (loops or dangling refs)\n  6. Dev B: TX path calls skb_segment(), crashes on corrupted frag_list\n\nRoot cause in skb_segment():\n  The check at line ~4891:\n    if (hsize <= 0 && i >= nfrags && skb_headlen(list_skb) &&\n        (skb_headlen(list_skb) == len || sg)) {\n\n  When frag_list is corrupted by double aggregation, when list_skb is\n  a NULL pointer from skb->next, skb_headlen(list_skb) dereference\n  NULL/corrupted pointers occurs.\n\nCall Trace:\n skb_headlen(NULL skb)\n skb_segment\n tcp_gso_segment\n tcp4_gso_segment\n inet_gso_segment\n skb_mac_gso_segment\n __skb_gso_segment\n skb_gso_segment\n validate_xmit_skb\n validate_xmit_skb_list\n sch_direct_xmit\n qdisc_restart\n __qdisc_run\n qdisc_run\n net_tx_action\n\nFix: Add NAPI_GRO_CB(skb)->flush validation to the early-return check in\nskb_gro_receive_list(), matching the defensive programming pattern of\nskb_gro_receive()."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:N - The bug is reached from the standard NAPI GRO receive path processing remotely originated TCP/IP packets (napi_gro_receive→dev_gro_receive→tcp_gro_receive→skb_gro_receive_list), including tethering/NAT/forwarding scenarios where packets re-enter GRO on a second netdev after driver LRO or prior GRO aggregation.\nAC:L - An attacker can reliably trigger the bug by crafting a TCP stream through a forwarding host with rx-gro-list enabled, without races or victim-specific timing; the commit documents a deterministic tethering/forwarding repro where flush-marked frag_list skbs are re-aggregated and later crash skb_segment.\nPR:N - No local privileges or authentication are required; any remote peer that can send TCP traffic through a vulnerable forwarding/tethering/NAT Linux host can reach the GRO fraglist merge path, which performs no capability or credential checks on the receive path.\nUI:N - Exploitation requires only network-delivered packets and normal kernel forwarding/GRO processing; the victim does not need to open files, mount filesystems, click links, or perform any deliberate action beyond routine network operation.\nS:U - Impact is confined to kernel memory corruption and panic within the same host kernel security domain during packet GRO aggregation and subsequent segmentation on transmit; it does not cross VM, container, or IOMMU boundaries to affect a separate security authority.\nC:H - Double aggregation corrupts the skb frag_list chain (loops, dangling references, NULL/corrupted list_skb pointers), constituting kernel heap memory corruption that can be read during skb_segment processing and is classifiable as a high-impact info-disclosure primitive beyond a simple crash.\nI:H - Re-aggregating flush-marked skbs with existing frag_list corrupts skb linked-list structure and reference relationships in kernel memory, enabling potential control of subsequent skb metadata and write/control-flow primitives during GSO segmentation, not merely integrity-preserving packet drops.\nA:H - Corrupted frag_list state causes skb_segment to dereference a NULL or invalid list_skb via skb_headlen(), producing a kernel panic/oops on the transmit path (sch_direct_xmit/qdisc_run), fully denying availability of the affected system."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/core/gro.c"
                    ],
                    "versions": [
                        {
                            "version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
                            "lessThan": "7fc7e35212cf58c134310fb47566a844297ceae9",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
                            "lessThan": "d1fb23f8f794ac4683127bd49a6422bd87e0ac02",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
                            "lessThan": "db3e82da616f52e2b27e25e7be3fde2f2a5e54d6",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
                            "lessThan": "107e1a469f53a2a70874f3f12bf6fcd23925da1d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
                            "lessThan": "a4dfd46cc8f08a29c6183794790547d0945f3d45",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
                            "lessThan": "fc0c0f7a207f0cd2d2aa725696c907f7d03af9e0",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
                            "lessThan": "e751256486d0ded20f5a9f9863467f1dce65142f",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/core/gro.c"
                    ],
                    "versions": [
                        {
                            "version": "5.6",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.6",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.266",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.184",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.153",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.101",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.42",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.1.6",
                            "lessThanOrEqual": "7.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.2",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.6",
                                    "versionEndExcluding": "5.10.266"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.6",
                                    "versionEndExcluding": "6.1.184"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.6",
                                    "versionEndExcluding": "6.6.153"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.6",
                                    "versionEndExcluding": "6.12.101"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.6",
                                    "versionEndExcluding": "6.18.42"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.6",
                                    "versionEndExcluding": "7.1.6"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.6",
                                    "versionEndExcluding": "7.2"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/7fc7e35212cf58c134310fb47566a844297ceae9"
                },
                {
                    "url": "https://git.kernel.org/stable/c/d1fb23f8f794ac4683127bd49a6422bd87e0ac02"
                },
                {
                    "url": "https://git.kernel.org/stable/c/db3e82da616f52e2b27e25e7be3fde2f2a5e54d6"
                },
                {
                    "url": "https://git.kernel.org/stable/c/107e1a469f53a2a70874f3f12bf6fcd23925da1d"
                },
                {
                    "url": "https://git.kernel.org/stable/c/a4dfd46cc8f08a29c6183794790547d0945f3d45"
                },
                {
                    "url": "https://git.kernel.org/stable/c/fc0c0f7a207f0cd2d2aa725696c907f7d03af9e0"
                },
                {
                    "url": "https://git.kernel.org/stable/c/e751256486d0ded20f5a9f9863467f1dce65142f"
                }
            ],
            "title": "net: gro: fix double aggregation of flush-marked skbs",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}