← All Advisories

Linux Kernel GRO Path Performs Double Aggregation of flush-Marked Skbs Because skb_gro_receive_list Lacks the Flush Check Added to skb_gro_receive

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-68136

Key Details

CVECVE-2026-68136
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-08-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: gro: fix double aggregation of flush-marked skbs

Commit 0ab03f353d36 ("net-gro: Fix GRO flush when receiving a GSO

packet.") added a flush check to skb_gro_receive(), but

skb_gro_receive_list() lacks the same validation.

As a result, packets marked with NAPI_GRO_CB(skb)->flush may still be

re-aggregated.

This allows already-GRO'd packets with existing frag_list to be

re-aggregated into a new GRO session, corrupting the frag_list chain

structure. When skb_segment() attempts to unpack these malformed packets,

it encounters invalid state and triggers a kernel panic.

Scenario (Tethering/Device forwarding):

1. Driver: Generated aggregated packet P1 via LRO with frag_list

2. Dev A: Receives aggregated fraglist packet and flush flag set

3. Dev A: Re-enters GRO, skb_gro_receive_list() is called

4. Missing flush check allows re-aggregation despite flush flag

5. Frag_list chain becomes corrupted (loops or dangling refs)

6. Dev B: TX path calls skb_segment(), crashes on corrupted frag_list

Root cause in skb_segment():

The check at line ~4891:

if (hsize <= 0 && i >= nfrags && skb_headlen(list_skb) &&

(skb_headlen(list_skb) == len || sg)) {

When frag_list is corrupted by double aggregation, when list_skb is

a NULL pointer from skb->next, skb_headlen(list_skb) dereference

NULL/corrupted pointers occurs.

Call Trace:

skb_headlen(NULL skb)

skb_segment

tcp_gso_segment

tcp4_gso_segment

inet_gso_segment

skb_mac_gso_segment

__skb_gso_segment

skb_gso_segment

validate_xmit_skb

validate_xmit_skb_list

sch_direct_xmit

qdisc_restart

__qdisc_run

qdisc_run

net_tx_action

Fix: Add NAPI_GRO_CB(skb)->flush validation to the early-return check in

skb_gro_receive_list(), matching the defensive programming pattern of

skb_gro_receive(). (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-68136
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-68136