CVE-2026-68385

Summary

In the Linux kernel, the following vulnerability has been resolved:

s390/checksum: Fix csum_partial() without vector facility

Currently csum_partial() calls csum_copy() with copy=false and dst=NULL. On machines without the vector facility, csum_copy() falls back to cksm(dst, …), causing the checksum to be calculated from address zero instead of the source buffer.

The VX implementation already checksums data loaded from src. Make the fallback do the same by passing src to cksm().

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxdcd3e1de9d17dc43dfed87a9fc814b9dec508043 < 5fc0a2a6eeb99cac991242bb48796c7749ce3261affected
LinuxLinuxdcd3e1de9d17dc43dfed87a9fc814b9dec508043 < 1d9a2f01b3c4e5c88e06b2db4b5460c2ec884722affected
LinuxLinuxdcd3e1de9d17dc43dfed87a9fc814b9dec508043 < 898bb2814f38399108bdd2113f38d97383a7036aaffected
LinuxLinuxdcd3e1de9d17dc43dfed87a9fc814b9dec508043 < 4bb06b60d982355e22647b3d12d6619419f8c1faaffected
LinuxLinux6.9affected
LinuxLinux0 < 6.9unaffected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc4 <= *unaffected

Weaknesses

References