CVE-2026-68123

Summary

In the Linux kernel, the following vulnerability has been resolved:

openvswitch: fix GSO userspace truncation underflow

OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb length in OVS_CB(skb)->cutlen. When a later userspace action segments a GSO skb, queue_gso_packets() reuses that delta for each smaller segment. A segment can then reach queue_userspace_packet() with cutlen greater than skb->len, underflowing the length passed to skb_zerocopy().

Store the maximum preserved length instead and bound each consumer against the current skb length. Use U32_MAX as the no-truncation sentinel so the value remains valid if skb geometry changes before a consumer handles it.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxf2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 < 50a6a85f3d6b1d22d8436848606cdef5d2c490b4affected
LinuxLinuxf2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 < 2623c48cc3a8da9a1886fd8f65c0e348f4406fd6affected
LinuxLinuxf2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 < e211b081901ffca76674082c73eeaed53524c369affected
LinuxLinuxf2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 < a16eaaf7c0b0ccdef6166707d90ffbc6eebf6855affected
LinuxLinuxf2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 < fbfa3ad2ad6f3a5624aba5211c46290fb98cc9dcaffected
LinuxLinuxf2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 < 100a23b1613e9218e0af654ef102352c713f0263affected
LinuxLinuxf2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 < ea85dbcbe8d4056ecb54352f97743d138ea4c407affected
LinuxLinuxf2a4d086ed4c588d32fe9b7aa67fead7280e7bf1 < 4032f8ed10fcb84d41c508dfb04be96589f78dfeaffected
LinuxLinux4.8affected
LinuxLinux0 < 4.8unaffected
LinuxLinux5.10.265 <= 5.10.*unaffected
LinuxLinux5.15.216 <= 5.15.*unaffected
LinuxLinux6.1.183 <= 6.1.*unaffected
LinuxLinux6.6.148 <= 6.6.*unaffected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References