๐Ÿ” CVE Alert

CVE-2026-68338

UNKNOWN 0.0

net/packet: avoid fanout hook re-registration after unregister

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/packet: avoid fanout hook re-registration after unregister packet_set_ring() temporarily detaches a socket from packet delivery while reconfiguring its ring. It records the previous running state, clears po->num, unregisters the protocol hook when needed, drops po->bind_lock, and later restores po->num and re-registers the hook from the saved was_running value. That unlocked window can race with NETDEV_UNREGISTER. The notifier can observe the socket as not running, skip __unregister_prot_hook(), and invalidate the per-socket binding by setting po->ifindex to -1 and clearing po->prot_hook.dev. A one-member fanout group can still retain its shared fanout hook device pointer. When packet_set_ring() resumes, re-registering solely from the stale was_running state can re-add the fanout hook after the device has been unregistered. Treat po->ifindex == -1 as an invalidated binding after reacquiring po->bind_lock. This is distinct from ifindex 0, the normal unbound/wildcard state: ifindex -1 marks an existing device binding that was invalidated when the device was unregistered. Restore po->num as before, but do not re-register the hook if device unregister already detached the socket.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
dc99f600698dcac69b8f56dda9a8a00d645c5ffc < 80ec024d53a05c60ad1d08968dcf745f10c1665c dc99f600698dcac69b8f56dda9a8a00d645c5ffc < 0a052e0808e015e68144a9877e6ef42b952c49fa dc99f600698dcac69b8f56dda9a8a00d645c5ffc < 1bc55c29cd85818e9052f17deb287d5a11fb817f dc99f600698dcac69b8f56dda9a8a00d645c5ffc < a885387dae7986a55bae5c77a15bdd447f64e9b9 dc99f600698dcac69b8f56dda9a8a00d645c5ffc < 50aff80475abd3533eef4320477037e6fcc6b56e
Linux / Linux
3.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/80ec024d53a05c60ad1d08968dcf745f10c1665c git.kernel.org: https://git.kernel.org/stable/c/0a052e0808e015e68144a9877e6ef42b952c49fa git.kernel.org: https://git.kernel.org/stable/c/1bc55c29cd85818e9052f17deb287d5a11fb817f git.kernel.org: https://git.kernel.org/stable/c/a885387dae7986a55bae5c77a15bdd447f64e9b9 git.kernel.org: https://git.kernel.org/stable/c/50aff80475abd3533eef4320477037e6fcc6b56e