Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-68129

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
10/08/2026
Última modificación:
19/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> gve: fix Rx queue stall on alloc failure<br /> <br /> When the system is under extreme memory pressure, page allocations can<br /> fail during the Rx buffer refill loop. If the number of buffers posted<br /> to hardware falls below a critical low threshold and the refill loop<br /> exits due to allocation failures, the queue can stall:<br /> <br /> 1. The device drops incoming packets because there are no descriptors.<br /> 2. Since no packets are processed, no Rx completions are generated.<br /> 3. Because no completions occur, NAPI is never scheduled, preventing<br /> the refill loop from running again even after memory is freed.<br /> <br /> This results in a permanent queue stall.<br /> <br /> Resolve this by introducing a starvation recovery timer for each Rx queue.<br /> If the number of buffers posted to hardware falls below a critical low<br /> threshold, start a timer to periodically reschedule NAPI. Once NAPI runs<br /> and successfully refills the queue above the threshold, the timer is<br /> not rescheduled.<br /> <br /> The threshold is set to 32 because a single maximum-sized Receive Segment<br /> Coalescing (RSC) packet can consume up to 19 descriptors in the Rx path.<br /> Lower thresholds (such as 8 or 16) would be insufficient to process a<br /> complete maximum-sized RSC packet, risking packet drops or unexpected<br /> hardware behavior under memory pressure. Setting the threshold to 32<br /> guarantees a safe margin to handle at least one full RSC packet.