CVE-2026-68123

Summary

In the Linux kernel, the following vulnerability has been resolved:

openvswitch: fix GSO userspace truncation underflow

OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb length in OVS_CB(skb)->cutlen. When a later userspace action segments a GSO skb, queue_gso_packets() reuses that delta for each smaller segment. A segment can then reach queue_userspace_packet() with cutlen greater than skb->len, underflowing the length passed to skb_zerocopy().

Store the maximum preserved length instead and bound each consumer against the current skb length. Use U32_MAX as the no-truncation sentinel so the value remains valid if skb geometry changes before a consumer handles it.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxf2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 < a16eaaf7c0b0ccdef6166707d90ffbc6eebf6855affected
LinuxLinuxf2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 < fbfa3ad2ad6f3a5624aba5211c46290fb98cc9dcaffected
LinuxLinuxf2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 < 100a23b1613e9218e0af654ef102352c713f0263affected
LinuxLinuxf2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 < ea85dbcbe8d4056ecb54352f97743d138ea4c407affected
LinuxLinuxf2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 < 4032f8ed10fcb84d41c508dfb04be96589f78dfeaffected
LinuxLinux4.8affected
LinuxLinux0 < 4.8unaffected
LinuxLinux6.6.148 <= 6.6.*unaffected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc5 <= *unaffected

Weaknesses

References