CVE-2026-68338
CVE CVE-2026-68338EUVD EUVD-2026-55439Published 2026-08-10T12:03:14.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: net/packet: avoid fanout hook re-registration after unregister packet_set_ring() temporarily detaches a socket from packet delivery while reconfiguring its ring. It records the previous running state, clears po->num, unregisters the protocol hook when needed, drops po->bind_lock, and later restores po->num and re-registers the hook from the saved was_running value. That unlocked window can race with NETDEV_UNREGISTER. The notifier can observe the socket as not running, skip __unregister_prot_hook(), and invalidate the per-socket binding by setting po->ifindex to -1 and clearing po->prot_hook.dev. A one-member fanout group can still retain its shared fanout hook device pointer. When packet_set_ring() resumes, re-registering solely from the stale was_running state can re-add the fanout hook after the device has been unregistered. Treat po->ifindex == -1 as an invalidated binding after reacquiring po->bind_lock. This is distinct from ifindex 0, the normal unbound/wildcard state: ifindex -1 marks an existing device binding that was invalidated when the device was unregistered. Restore po->num as before, but do not re-register the hook if device unregister already detached the socket.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux dc99f600698dcac69b8f56dda9a8a00d645c5ffc <a885387dae7986a55bae5c77a15bdd447f64e9b9; dc99f600698dcac69b8f56dda9a8a00d645c5ffc <0a052e0808e015e68144a9877e6ef42b952c49fa; patch: 7.1.6; 3.1; dc99f600698dcac69b8f56dda9a8a00d645c5ffc <80ec024d53a05c60ad1d08968dcf745f10c1665c; dc99f600698dcac69b8f56dda9a8a00d645c5ffc <1bc55c29cd85818e9052f17deb287d5a11fb817f; patch: 6.12.101; patch: 0; patch: 6.6.148; dc99f600698dcac69b8f56dda9a8a00d645c5ffc <50aff80475abd3533eef4320477037e6fcc6b56e; patch: 7.2-rc5; patch: 6.18.42
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.