CRITICAL Introduced in 5.6
gro FragList Corruption
CVE-2026-68136
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.5HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: net: gro: fix double aggregation of flush-marked skbs Commit 0ab03f353d36 ("net-gro: Fix GRO flush when receiving a GSO packet.") added a flush check to skb_gro_receive(), but skb_gro_receive_list() lacks the same validation. As a result, packets marked with NAPI_GRO_CB(skb)->flush may still be re-aggregated. This allows already-GRO'd packets with existing frag_list to be re-aggregated into a new GRO session, corrupting the frag_list chain structure. When skb_segment() attempts to unpack these malformed packets, it encounters invalid state and triggers a kernel panic. Scenario (Tethering/Device forwarding): 1. Driver: Generated aggregated packet P1 via LRO with frag_list 2. Dev A: Receives aggregated fraglist packet and flush flag set 3. Dev A: Re-enters GRO, skb_gro_receive_list() is called 4. Missing flush check allows re-aggregation despite flush flag 5. Frag_list chain becomes corrupted (loops or dangling refs) 6. Dev B: TX path calls skb_segment(), crashes on corrupted frag_list Root cause in skb_segment(): The check at line ~4891: if (hsize <= 0 && i >= nfrags && skb_headlen(list_skb) && (skb_headlen(list_skb) == len || sg)) { When frag_list is corrupted by double aggregation, when list_skb is a NULL pointer from skb->next, skb_headlen(list_skb) dereference NULL/corrupted pointers occurs. Call Trace: skb_headlen(NULL skb) skb_segment tcp_gso_segment tcp4_gso_segment inet_gso_segment skb_mac_gso_segment __skb_gso_segment skb_gso_segment validate_xmit_skb validate_xmit_skb_list sch_direct_xmit qdisc_restart __qdisc_run qdisc_run net_tx_action Fix: Add NAPI_GRO_CB(skb)->flush validation to the early-return check in skb_gro_receive_list(), matching the defensive programming pattern of skb_gro_receive().
02KernelScan AI Analysis
Risk summary
A remote attacker sending network traffic to a device that receives packets on an LRO-capable interface and forwards them can trigger a kernel panic. The bug is in the GRO receive path where already-aggregated packets marked for flushing are improperly re-aggregated, corrupting internal packet chain structures. When the corrupted packet is later segmented for transmission, the kernel dereferences a NULL pointer and crashes.
Vulnerability analysis
Packets that have already been hardware-aggregated and marked to be flushed can be merged again by the network receive-offload path because that path fails to check the flush marker. This duplicate merge corrupts the internal packet chain, creating loops or invalid references. When the corrupted packet is later split apart for transmission on the outgoing interface, the splitting code traverses the damaged chain, dereferences an invalid pointer, and crashes the kernel. The fix adds the missing flush check to the secondary merge path so that marked packets are not merged again. An attacker can trigger this by sending network traffic to a device that receives packets through a hardware-offload-capable interface and forwards them to another interface, such as a tethering or routing gateway; no privileges on the target device are required.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 5.6 | 6.12.101 | 107e1a469f53 |
| 6.18 | 5.6 | 6.18.42 | a4dfd46cc8f0 |
| 7.1 | 5.6 | 7.1.6 | fc0c0f7a207f |
| 5.10 | 5.6 | 5.10.266 | 7fc7e35212cf |
| 6.1 | 5.6 | 6.1.184 | d1fb23f8f794 |
| 6.6 | 5.6 | 6.6.153 | db3e82da616f |
| mainline | 5.6 | 7.2 | e751256486d0 |