PT-2026-69699 · Linux · Linux Kernel
CVE-2026-68299
·
Published
2026-08-10
·
Updated
2026-08-12
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
vmxnet3 get hdr len() function where it incorrectly assumes that gdesc->rcd.v4, gdesc->rcd.v6, and gdesc->rcd.tcp always describe the outer header. For Geneve-encapsulated packets, the device may set these based on the inner header, indicated by the VMXNET3 RCD HDR INNER SHIFT bit in the completion descriptor. Because the function does not skip the outer encapsulation, this mismatch can trigger a system crash via BUG ON() when the outer protocol is UDP instead of TCP, or when the outer and inner IP versions differ.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel