CVE-2026-68123
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
19/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
openvswitch: fix GSO userspace truncation underflow<br />
<br />
OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb<br />
length in OVS_CB(skb)->cutlen. When a later userspace action segments a<br />
GSO skb, queue_gso_packets() reuses that delta for each smaller segment.<br />
A segment can then reach queue_userspace_packet() with cutlen greater<br />
than skb->len, underflowing the length passed to skb_zerocopy().<br />
<br />
Store the maximum preserved length instead and bound each consumer<br />
against the current skb length. Use U32_MAX as the no-truncation<br />
sentinel so the value remains valid if skb geometry changes before a<br />
consumer handles it.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/100a23b1613e9218e0af654ef102352c713f0263
- https://git.kernel.org/stable/c/2623c48cc3a8da9a1886fd8f65c0e348f4406fd6
- https://git.kernel.org/stable/c/4032f8ed10fcb84d41c508dfb04be96589f78dfe
- https://git.kernel.org/stable/c/50a6a85f3d6b1d22d8436848606cdef5d2c490b4
- https://git.kernel.org/stable/c/a16eaaf7c0b0ccdef6166707d90ffbc6eebf6855
- https://git.kernel.org/stable/c/e211b081901ffca76674082c73eeaed53524c369
- https://git.kernel.org/stable/c/ea85dbcbe8d4056ecb54352f97743d138ea4c407
- https://git.kernel.org/stable/c/fbfa3ad2ad6f3a5624aba5211c46290fb98cc9dc


