CVE-2026-68338
Received Received - Intake

Race Condition in Linux Kernel Packet Socket Handling

Vulnerability report for CVE-2026-68338, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: net/packet: avoid fanout hook re-registration after unregister packet_set_ring() temporarily detaches a socket from packet delivery while reconfiguring its ring. It records the previous running state, clears po->num, unregisters the protocol hook when needed, drops po->bind_lock, and later restores po->num and re-registers the hook from the saved was_running value. That unlocked window can race with NETDEV_UNREGISTER. The notifier can observe the socket as not running, skip __unregister_prot_hook(), and invalidate the per-socket binding by setting po->ifindex to -1 and clearing po->prot_hook.dev. A one-member fanout group can still retain its shared fanout hook device pointer. When packet_set_ring() resumes, re-registering solely from the stale was_running state can re-add the fanout hook after the device has been unregistered. Treat po->ifindex == -1 as an invalidated binding after reacquiring po->bind_lock. This is distinct from ifindex 0, the normal unbound/wildcard state: ifindex -1 marks an existing device binding that was invalidated when the device was unregistered. Restore po->num as before, but do not re-register the hook if device unregister already detached the socket.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a race condition in the packet_set_ring() function. When reconfiguring a socket's ring, the function temporarily detaches the socket from packet delivery. A window exists where another process (NETDEV_UNREGISTER) can invalidate the socket's device binding by setting po->ifindex to -1. Later, packet_set_ring() may incorrectly re-register a fanout hook using stale data, leading to potential use-after-free or other memory corruption issues.

Impact Analysis

This vulnerability could allow an attacker to cause a denial of service, crash the system, or potentially execute arbitrary code with kernel privileges. It affects systems using packet sockets, which are commonly used for network monitoring and packet capture tools.

Mitigation Strategies

Update the Linux kernel to the latest patched version to resolve this issue. Monitor kernel security advisories and apply updates promptly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68338. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart