CVE-2026-68338
Last modified
CVE-2026-68338 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: net/packet: avoid fanout hook re-registration after unregister packet_set_ring() temporarily detaches a socket from packet delivery while reconfiguring its ring. It records the previous running state, clears po->num, unregisters the protocol hook when needed, drops po->bind_lock, and later restores po->num and re-registers the hook from the saved was_running value. That unlocked window can race with NETDEV_UNREGISTER.
Description
In the Linux kernel, the following vulnerability has been resolved: net/packet: avoid fanout hook re-registration after unregister packet_set_ring() temporarily detaches a socket from packet delivery while reconfiguring its ring. It records the previous running state, clears po->num, unregisters the protocol hook when needed, drops po->bind_lock, and later restores po->num and re-registers the hook from the saved was_running value. That unlocked window can race with NETDEV_UNREGISTER. The notifier can observe the socket as not running, skip __unregister_prot_hook(), and invalidate the per-socket binding by setting po->ifindex to -1 and clearing po->prot_hook.dev. A one-member fanout group can still retain its shared fanout hook device pointer. When packet_set_ring() resumes, re-registering solely from the stale was_running state can re-add the fanout hook after the device has been unregistered. Treat po->ifindex == -1 as an invalidated binding after reacquiring po->bind_lock. This is distinct from ifindex 0, the normal unbound/wildcard state: ifindex -1 marks an existing device binding that was invalidated when the device was unregistered. Restore po->num as before, but do not re-register the hook if device unregister already detached the socket.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= dc99f600698dcac69b8f56dda9a8a00d645c5ffc, < 80ec024d53a05c60ad1d08968dcf745f10c1665c; >= dc99f600698dcac69b8f56dda9a8a00d645c5ffc, < 0a052e0808e015e68144a9877e6ef42b952c49fa; >= dc99f600698dcac69b8f56dda9a8a00d645c5ffc, < 1bc55c29cd85818e9052f17deb287d5a11fb817f; >= dc99f600698dcac69b8f56dda9a8a00d645c5ffc, < a885387dae7986a55bae5c77a15bdd447f64e9b9; >= dc99f600698dcac69b8f56dda9a8a00d645c5ffc, < 50aff80475abd3533eef4320477037e6fcc6b56e |
| Linux | Linux | 3.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68338?
How severe is CVE-2026-68338?
How do I fix CVE-2026-68338?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68332In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68333In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68334In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68335In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68336In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68337In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68339In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6834The a+HRD developed by aEnrich has a Missing Authorization v…7.1
- CVE-2026-68340In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68341In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68342In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68343In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-68338?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
