Answer in brief
CVE-2026-68299 records a High severity (CVSS 7.5) vulnerability in vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc <667b6e52048eaf4dbcf1707ed87ffd44abb9cb38 || >=45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc <28cb5d8d13b4c1faf3f688f62e5df82fe7b438d8 || >=45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc <4fdb0f162ccdbe9626863b10003855703253fa29 || >=45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc <b28596baf87e25a078789f1c05817c8a3bf71257 || >=45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc <34a71f5361fc3adb5b7138da78750b0d535a8252 | 667b6e52048eaf4dbcf1707ed87ffd44abb9cb38, 28cb5d8d13b4c1faf3f688f62e5df82fe7b438d8, 4fdb0f162ccdbe9626863b10003855703253fa29, b28596baf87e25a078789f1c05817c8a3bf71257, 34a71f5361fc3adb5b7138da78750b0d535a8252 |
| Linux/Linuxgeneric | 4.2 | Not reported |
| Linux/Linuxgeneric | >=45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc <2ddf51fcb6dd7d55ceef38e2e1a5ab2ab7fd47b0 || >=45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc <fbab6b73cc086e32698c86e43d1b16bf17d24c36 || >=45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc <28e382646417c7e2be9c9a7079eddf627ff52b90 || >=45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc <667b6e52048eaf4dbcf1707ed87ffd44abb9cb38 || >=45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc <28cb5d8d13b4c1faf3f688f62e5df82fe7b438d8 || >=45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc <4fdb0f162ccdbe9626863b10003855703253fa29 || >=45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc <b28596baf87e25a078789f1c05817c8a3bf71257 || >=45dac1d6ea045ae56e4df8d9c70c92c7412bd4fc <34a71f5361fc3adb5b7138da78750b0d535a8252 | 2ddf51fcb6dd7d55ceef38e2e1a5ab2ab7fd47b0, fbab6b73cc086e32698c86e43d1b16bf17d24c36, 28e382646417c7e2be9c9a7079eddf627ff52b90, 667b6e52048eaf4dbcf1707ed87ffd44abb9cb38, 28cb5d8d13b4c1faf3f688f62e5df82fe7b438d8, 4fdb0f162ccdbe9626863b10003855703253fa29, b28596baf87e25a078789f1c05817c8a3bf71257, 34a71f5361fc3adb5b7138da78750b0d535a8252 |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them based on the inner header instead, signalled by the VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the function never skips the outer encapsulation, this mismatch triggers: - BUG_ON(hdr.ipv4->protocol != IPPROTO_TCP), because the outer protocol is UDP (Geneve), not TCP. - BUG_ON(hdr.eth->h_proto != ...), when the tunnel's outer and inner IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa). Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the function cannot locate the inner header it would need to parse. Also convert the remaining BUG_ON()s in this function to return 0 defensively.
Quoted source text, attributed separately from HOL analysis.