« Volver al listado

CVE-2026-68296

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM

Before commit 00d066a4d4ed ("netdev_features: convert NETIF_F_LLTX to dev->lltx"), NETIF_F_LLTX was set unconditionally in both __gre_tunnel_init() and ip6gre_tnl_init_features() alongside GRE_FEATURES:

When that commit converted NETIF_F_LLTX to the dev->lltx flag, it placed 'dev->lltx = true' after the SEQ/CSUM early returns instead of before them. This causes GRE/GRETAP/ip6gre tunnels with SEQ or CSUM+encap to lose lockless TX, reintroducing _xmit_lock acquisition around their ndo_start_xmit. Since GRE xmit re-enters the stack via ip_tunnel_xmit(), holding _xmit_lock risks ABBA deadlock with the underlay device.

Leer descripción completaMostrar menos

Fix by moving dev->lltx = true before the early returns in both functions, restoring the original unconditional behavior.

Detalles técnicos trazas, registros y código del informe original
    dev->features |= GRE_FEATURES | NETIF_F_LLTX;

  CPU0                        CPU1
  ----                        ----
  lock(&qdisc_xmit_lock_key#6);
                              lock(&qdisc_xmit_lock_key#3);
                              lock(&qdisc_xmit_lock_key#6);
  lock(&qdisc_xmit_lock_key#3);

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68296",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "00d066a4d4edbe559ba6c35153da71d4b2b8a383",
              "lessThan": "9f948e9aede9678f4103457daf2bc9dd54c65a06",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "00d066a4d4edbe559ba6c35153da71d4b2b8a383",
              "lessThan": "15a1c5f2ed2eeb3daad8d5766fd506aeda4710f3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "00d066a4d4edbe559ba6c35153da71d4b2b8a383",
              "lessThan": "2bffe379023512d280337c70faeb6a8cc435db5e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "00d066a4d4edbe559ba6c35153da71d4b2b8a383",
              "lessThan": "675ed582c1aa4d919dd535490de08c015005c653",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/ipv4/ip_gre.c",
            "net/ipv6/ip6_gre.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.101",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/ipv4/ip_gre.c",
            "net/ipv6/ip6_gre.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:20:19.053",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/15a1c5f2ed2eeb3daad8d5766fd506aeda4710f3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2bffe379023512d280337c70faeb6a8cc435db5e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/675ed582c1aa4d919dd535490de08c015005c653",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9f948e9aede9678f4103457daf2bc9dd54c65a06",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gre: fix lltx regression for GRE tunnels with SEQ/CSUM\n\nBefore commit 00d066a4d4ed (\"netdev_features: convert NETIF_F_LLTX to\ndev->lltx\"), NETIF_F_LLTX was set unconditionally in both\n__gre_tunnel_init() and ip6gre_tnl_init_features() alongside\nGRE_FEATURES:\n\n    dev->features |= GRE_FEATURES | NETIF_F_LLTX;\n\nWhen that commit converted NETIF_F_LLTX to the dev->lltx flag, it\nplaced 'dev->lltx = true' after the SEQ/CSUM early returns instead\nof before them. This causes GRE/GRETAP/ip6gre tunnels with SEQ or\nCSUM+encap to lose lockless TX, reintroducing _xmit_lock acquisition\naround their ndo_start_xmit. Since GRE xmit re-enters the stack via\nip_tunnel_xmit(), holding _xmit_lock risks ABBA deadlock with the\nunderlay device.\n\n  CPU0                        CPU1\n  ----                        ----\n  lock(&qdisc_xmit_lock_key#6);\n                              lock(&qdisc_xmit_lock_key#3);\n                              lock(&qdisc_xmit_lock_key#6);\n  lock(&qdisc_xmit_lock_key#3);\n\nFix by moving dev->lltx = true before the early returns in both\nfunctions, restoring the original unconditional behavior."
    }
  ],
  "lastModified": "2026-08-17T05:18:32.323",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}