← All Advisories

CVE-2026-68286

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-68286

Key Details

CVECVE-2026-68286
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

drop_monitor: perform u64_stats updates under IRQ-disabled section

In net_dm_packet_trace_kfree_skb_hit() and net_dm_hw_trap_packet_probe(),

u64_stats_update_begin() / u64_stats_inc() / u64_stats_update_end() were

called after spin_unlock_irqrestore(&...drop_queue.lock, flags), when local

IRQs had already been re-enabled.

Tracepoint probes can execute in IRQ or softirq context. On 32-bit

architectures, u64_stats_update_begin() disables preemption but not interrupts,

relying on seqcount writes. If a nested interrupt occurs on the same CPU during

the 64-bit stats update, the reentrant seqcount update can corrupt the

seqcount state or stats value.

Fix this by performing the 64-bit per-CPU stats update before releasing

drop_queue.lock via spin_unlock_irqrestore(), ensuring local interrupts remain

disabled during the u64_stats update. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-68286
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-68286