CVE-2026-68123
CVE CVE-2026-68123EUVD EUVD-2026-55504Published 2026-08-10T11:58:43.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix GSO userspace truncation underflow OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb length in OVS_CB(skb)->cutlen. When a later userspace action segments a GSO skb, queue_gso_packets() reuses that delta for each smaller segment. A segment can then reach queue_userspace_packet() with cutlen greater than skb->len, underflowing the length passed to skb_zerocopy(). Store the maximum preserved length instead and bound each consumer against the current skb length. Use U32_MAX as the no-truncation sentinel so the value remains valid if skb geometry changes before a consumer handles it.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 <100a23b1613e9218e0af654ef102352c713f0263; patch: 7.1.6; patch: 6.6.148; f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 <a16eaaf7c0b0ccdef6166707d90ffbc6eebf6855; f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 <4032f8ed10fcb84d41c508dfb04be96589f78dfe; patch: 6.12.101; patch: 7.2-rc5; patch: 6.18.42; patch: 0; f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 <ea85dbcbe8d4056ecb54352f97743d138ea4c407; f2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 <fbfa3ad2ad6f3a5624aba5211c46290fb98cc9dc; 4.8
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.