PT-2026-69699 · Linux · Linux Kernel

CVE-2026-68299

·

Published

2026-08-10

·

Updated

2026-08-12

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the vmxnet3 get hdr len() function where it incorrectly assumes that gdesc->rcd.v4, gdesc->rcd.v6, and gdesc->rcd.tcp always describe the outer header. For Geneve-encapsulated packets, the device may set these based on the inner header, indicated by the VMXNET3 RCD HDR INNER SHIFT bit in the completion descriptor. Because the function does not skip the outer encapsulation, this mismatch can trigger a system crash via BUG ON() when the outer protocol is UDP instead of TCP, or when the outer and inner IP versions differ.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-68299

Affected Products

Linux Kernel