CVE-2026-68426

Source
https://cve.org/CVERecord?id=CVE-2026-68426
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68426.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68426
Downstream
Published
2026-08-10T12:04:46.945Z
Modified
2026-08-12T04:24:32.738288584Z
Summary
xfrm: fix stale skb->prev after async crypto steals a GSO segment
Details

In the Linux kernel, the following vulnerability has been resolved:

xfrm: fix stale skb->prev after async crypto steals a GSO segment

skbgsosegment() leaves the segment list head with ->prev pointing at the last segment, an invariant validatexmitskb_list() relies on when it sets its tail pointer (tail = skb->prev).

When validatexmitxfrm() walks a GSO list and some segments are stolen by async crypto (->xmit() returns -EINPROGRESS), those segments are unlinked from the list but the head ->prev is never updated. If the last segment is the one stolen, the returned head still has ->prev pointing at it, even though it is now owned by the crypto engine and may be freed. validatexmitskb_list() later does tail->next = skb, writing through that stale pointer -- a use-after-free.

Repoint skb->prev at the last retained segment before returning.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68426.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f53c723902d1ac5f0b0a11d7c9dcbff748dde74e
Fixed
33e1b0d25ca0d2818c635ff80e6aa0d295e08a98
Fixed
bbca7cc3b2b4b10afbfee99b81d9ee78f5423046
Fixed
3f4c3919baf0944ad96580467c302bc6c7758b00

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68426.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.16.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68426.json"