CVE-2026-68296
net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
Description
In the Linux kernel, the following vulnerability has been resolved: net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM Before commit 00d066a4d4ed ("netdev_features: convert NETIF_F_LLTX to dev->lltx"), NETIF_F_LLTX was set unconditionally in both __gre_tunnel_init() and ip6gre_tnl_init_features() alongside GRE_FEATURES: dev->features |= GRE_FEATURES | NETIF_F_LLTX; When that commit converted NETIF_F_LLTX to the dev->lltx flag, it placed 'dev->lltx = true' after the SEQ/CSUM early returns instead of before them. This causes GRE/GRETAP/ip6gre tunnels with SEQ or CSUM+encap to lose lockless TX, reintroducing _xmit_lock acquisition around their ndo_start_xmit. Since GRE xmit re-enters the stack via ip_tunnel_xmit(), holding _xmit_lock risks ABBA deadlock with the underlay device. CPU0 CPU1 ---- ---- lock(&qdisc_xmit_lock_key#6); lock(&qdisc_xmit_lock_key#3); lock(&qdisc_xmit_lock_key#6); lock(&qdisc_xmit_lock_key#3); Fix by moving dev->lltx = true before the early returns in both functions, restoring the original unconditional behavior.
INFO
Published Date :
Aug. 10, 2026, 1:20 p.m.
Last Modified :
Aug. 17, 2026, 5:18 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
- Apply kernel patch to move dev->lltx = true.
- Ensure dev->lltx is set before early returns.
- Test GRE/GRETAP/ip6gre tunnel transmission.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-68296.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-68296 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-68296
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-68296 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-68296 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 17, 2026
Action Type Old Value New Value Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '9f948e9aede9678f4103457daf2bc9dd54c65a06', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '15a1c5f2ed2eeb3daad8d5766fd506aeda4710f3', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '2bffe379023512d280337c70faeb6a8cc435db5e', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '675ed582c1aa4d919dd535490de08c015005c653', 'versionType': 'git'}], 'programFiles': ['net/ipv4/ip_gre.c', 'net/ipv6/ip6_gre.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.12'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.12', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc5', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/ipv4/ip_gre.c', 'net/ipv6/ip6_gre.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '9f948e9aede9678f4103457daf2bc9dd54c65a06', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '15a1c5f2ed2eeb3daad8d5766fd506aeda4710f3', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '2bffe379023512d280337c70faeb6a8cc435db5e', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '675ed582c1aa4d919dd535490de08c015005c653', 'versionType': 'git'}], 'programFiles': ['net/ipv4/ip_gre.c', 'net/ipv6/ip6_gre.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.12'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.12', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/ipv4/ip_gre.c', 'net/ipv6/ip6_gre.c'], 'defaultStatus': 'affected'}] -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 10, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '9f948e9aede9678f4103457daf2bc9dd54c65a06', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '15a1c5f2ed2eeb3daad8d5766fd506aeda4710f3', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '2bffe379023512d280337c70faeb6a8cc435db5e', 'versionType': 'git'}, {'status': 'affected', 'version': '00d066a4d4edbe559ba6c35153da71d4b2b8a383', 'lessThan': '675ed582c1aa4d919dd535490de08c015005c653', 'versionType': 'git'}], 'programFiles': ['net/ipv4/ip_gre.c', 'net/ipv6/ip6_gre.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.12'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.12', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.6', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc5', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/ipv4/ip_gre.c', 'net/ipv6/ip6_gre.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM Before commit 00d066a4d4ed ("netdev_features: convert NETIF_F_LLTX to dev->lltx"), NETIF_F_LLTX was set unconditionally in both __gre_tunnel_init() and ip6gre_tnl_init_features() alongside GRE_FEATURES: dev->features |= GRE_FEATURES | NETIF_F_LLTX; When that commit converted NETIF_F_LLTX to the dev->lltx flag, it placed 'dev->lltx = true' after the SEQ/CSUM early returns instead of before them. This causes GRE/GRETAP/ip6gre tunnels with SEQ or CSUM+encap to lose lockless TX, reintroducing _xmit_lock acquisition around their ndo_start_xmit. Since GRE xmit re-enters the stack via ip_tunnel_xmit(), holding _xmit_lock risks ABBA deadlock with the underlay device. CPU0 CPU1 ---- ---- lock(&qdisc_xmit_lock_key#6); lock(&qdisc_xmit_lock_key#3); lock(&qdisc_xmit_lock_key#6); lock(&qdisc_xmit_lock_key#3); Fix by moving dev->lltx = true before the early returns in both functions, restoring the original unconditional behavior. Added Reference https://git.kernel.org/stable/c/15a1c5f2ed2eeb3daad8d5766fd506aeda4710f3 Added Reference https://git.kernel.org/stable/c/2bffe379023512d280337c70faeb6a8cc435db5e Added Reference https://git.kernel.org/stable/c/675ed582c1aa4d919dd535490de08c015005c653 Added Reference https://git.kernel.org/stable/c/9f948e9aede9678f4103457daf2bc9dd54c65a06