0.0
NA
CVE-2026-68296
net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
Description

In the Linux kernel, the following vulnerability has been resolved: net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM Before commit 00d066a4d4ed ("netdev_features: convert NETIF_F_LLTX to dev->lltx"), NETIF_F_LLTX was set unconditionally in both __gre_tunnel_init() and ip6gre_tnl_init_features() alongside GRE_FEATURES: dev->features |= GRE_FEATURES | NETIF_F_LLTX; When that commit converted NETIF_F_LLTX to the dev->lltx flag, it placed 'dev->lltx = true' after the SEQ/CSUM early returns instead of before them. This causes GRE/GRETAP/ip6gre tunnels with SEQ or CSUM+encap to lose lockless TX, reintroducing _xmit_lock acquisition around their ndo_start_xmit. Since GRE xmit re-enters the stack via ip_tunnel_xmit(), holding _xmit_lock risks ABBA deadlock with the underlay device. CPU0 CPU1 ---- ---- lock(&qdisc_xmit_lock_key#6); lock(&qdisc_xmit_lock_key#3); lock(&qdisc_xmit_lock_key#6); lock(&qdisc_xmit_lock_key#3); Fix by moving dev->lltx = true before the early returns in both functions, restoring the original unconditional behavior.

INFO

Published Date :

Aug. 10, 2026, 1:20 p.m.

Last Modified :

Aug. 17, 2026, 5:18 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-68296 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Revert lockless transmission changes for GRE tunnels to prevent deadlock.
  • Apply kernel patch to move dev->lltx = true.
  • Ensure dev->lltx is set before early returns.
  • Test GRE/GRETAP/ip6gre tunnel transmission.
References to Advisories, Solutions, and Tools
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-68296 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-68296 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-68296 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-68296 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 17, 2026

    Action Type Old Value New Value
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '9f948e9aede9678f4103457daf2bc9dd54c65a06', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '15a1c5f2ed2eeb3daad8d5766fd506aeda4710f3', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '2bffe379023512d280337c70faeb6a8cc435db5e', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '675ed582c1aa4d919dd535490de08c015005c653', 'versionType': 'git'}], 'programFiles': ['net/ipv4/ip_gre.c', 'net/ipv6/ip6_gre.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.12'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.12', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc5', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/ipv4/ip_gre.c', 'net/ipv6/ip6_gre.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '9f948e9aede9678f4103457daf2bc9dd54c65a06', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '15a1c5f2ed2eeb3daad8d5766fd506aeda4710f3', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '2bffe379023512d280337c70faeb6a8cc435db5e', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '675ed582c1aa4d919dd535490de08c015005c653', 'versionType': 'git'}], 'programFiles': ['net/ipv4/ip_gre.c', 'net/ipv6/ip6_gre.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.12'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.12', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/ipv4/ip_gre.c', 'net/ipv6/ip6_gre.c'], 'defaultStatus': 'affected'}]
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 10, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '9f948e9aede9678f4103457daf2bc9dd54c65a06', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '15a1c5f2ed2eeb3daad8d5766fd506aeda4710f3', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '2bffe379023512d280337c70faeb6a8cc435db5e', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '675ed582c1aa4d919dd535490de08c015005c653', 'versionType': 'git'}], 'programFiles': ['net/ipv4/ip_gre.c', 'net/ipv6/ip6_gre.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.12'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.12', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc5', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/ipv4/ip_gre.c', 'net/ipv6/ip6_gre.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM Before commit 00d066a4d4ed ("netdev_features: convert NETIF_F_LLTX to dev->lltx"), NETIF_F_LLTX was set unconditionally in both __gre_tunnel_init() and ip6gre_tnl_init_features() alongside GRE_FEATURES: dev->features |= GRE_FEATURES | NETIF_F_LLTX; When that commit converted NETIF_F_LLTX to the dev->lltx flag, it placed 'dev->lltx = true' after the SEQ/CSUM early returns instead of before them. This causes GRE/GRETAP/ip6gre tunnels with SEQ or CSUM+encap to lose lockless TX, reintroducing _xmit_lock acquisition around their ndo_start_xmit. Since GRE xmit re-enters the stack via ip_tunnel_xmit(), holding _xmit_lock risks ABBA deadlock with the underlay device. CPU0 CPU1 ---- ---- lock(&qdisc_xmit_lock_key#6); lock(&qdisc_xmit_lock_key#3); lock(&qdisc_xmit_lock_key#6); lock(&qdisc_xmit_lock_key#3); Fix by moving dev->lltx = true before the early returns in both functions, restoring the original unconditional behavior.
    Added Reference https://git.kernel.org/stable/c/15a1c5f2ed2eeb3daad8d5766fd506aeda4710f3
    Added Reference https://git.kernel.org/stable/c/2bffe379023512d280337c70faeb6a8cc435db5e
    Added Reference https://git.kernel.org/stable/c/675ed582c1aa4d919dd535490de08c015005c653
    Added Reference https://git.kernel.org/stable/c/9f948e9aede9678f4103457daf2bc9dd54c65a06
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.