← All Advisories

CVE-2026-68287

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-68287

Key Details

CVECVE-2026-68287
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

drop_monitor: fix size calculations for 64-bit attributes

net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() use

nla_put_u64_64bit() to append 64-bit attributes (NET_DM_ATTR_PC and

NET_DM_ATTR_TIMESTAMP).

On 32-bit architectures without CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS,

nla_put_u64_64bit() may append a 4-byte NET_DM_ATTR_PAD attribute for

64-bit alignment.

However, net_dm_packet_report_size() and net_dm_hw_packet_report_size()

used nla_total_size(sizeof(u64)) instead of nla_total_size_64bit(sizeof(u64)),

budgeting 12 bytes instead of up to 16 bytes.

This under-estimation of SKB size can lead to an skb_over_panic() when

__nla_reserve() or skb_put() is subsequently called.

Fix this by using nla_total_size_64bit(sizeof(u64)) in both size calculations. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-68287
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-68287