Junglewise Threat Intelligence

CVE-2026-68136: Linux kernel GRO double aggregation denial of service

CVE-2026-68136 · Severity: critical · CVSS 9.8 · Published 2026-08-10

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's network packet processing logic contains a flaw that allows specially constructed network packets to be incorrectly re-aggregated, corrupting internal data structures. This causes the kernel to crash when attempting to transmit the malformed packets, leading to service unavailability on affected systems. Attackers on the network path can exploit this to cause denial of service without authentication.

Technical details

The vulnerability exists in the GRO (Generic Receive Offload) subsystem of the Linux kernel. The function skb_gro_receive_list() lacks a flush check that was added to skb_gro_receive() in a prior commit. Packets marked with NAPI_GRO_CB(skb)->flush can be re-aggregated despite their flush flag, corrupting the frag_list chain structure. When skb_segment() later attempts to unpack these malformed packets during transmission, it dereferences invalid pointers in the corrupted frag_list, triggering a kernel panic. The attack vector is network-based and requires no authentication; an attacker on the network path (e.g., tethering/device forwarding scenario) can send crafted GRO packets to trigger the crash. A patch is available that adds the missing flush validation to skb_gro_receive_list().

Affected products

  • Linux Linux kernel <UNKNOWN>

Timeline

  • 2026-08-10: disclosed: CVE published

Related threats