Answer in brief
CVE-2026-68338 records a High severity (CVSS 7.8) vulnerability in net/packet: avoid fanout hook re-registration after unregister. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=dc99f600698dcac69b8f56dda9a8a00d645c5ffc <80ec024d53a05c60ad1d08968dcf745f10c1665c || >=dc99f600698dcac69b8f56dda9a8a00d645c5ffc <0a052e0808e015e68144a9877e6ef42b952c49fa || >=dc99f600698dcac69b8f56dda9a8a00d645c5ffc <1bc55c29cd85818e9052f17deb287d5a11fb817f || >=dc99f600698dcac69b8f56dda9a8a00d645c5ffc <a885387dae7986a55bae5c77a15bdd447f64e9b9 || >=dc99f600698dcac69b8f56dda9a8a00d645c5ffc <50aff80475abd3533eef4320477037e6fcc6b56e | 80ec024d53a05c60ad1d08968dcf745f10c1665c, 0a052e0808e015e68144a9877e6ef42b952c49fa, 1bc55c29cd85818e9052f17deb287d5a11fb817f, a885387dae7986a55bae5c77a15bdd447f64e9b9, 50aff80475abd3533eef4320477037e6fcc6b56e |
| Linux/Linuxgeneric | 3.1 | Not reported |
| Linux/Linuxgeneric | >=dc99f600698dcac69b8f56dda9a8a00d645c5ffc <acb40ebfa5c4d62f84339fcbf713f2a9fd033a71 || >=dc99f600698dcac69b8f56dda9a8a00d645c5ffc <c820f4b7f2fa38f8769db0d0cefdd94e2721504d || >=dc99f600698dcac69b8f56dda9a8a00d645c5ffc <4628efbdc7affd094181f5263e65c1062e31f15f || >=dc99f600698dcac69b8f56dda9a8a00d645c5ffc <80ec024d53a05c60ad1d08968dcf745f10c1665c || >=dc99f600698dcac69b8f56dda9a8a00d645c5ffc <0a052e0808e015e68144a9877e6ef42b952c49fa || >=dc99f600698dcac69b8f56dda9a8a00d645c5ffc <1bc55c29cd85818e9052f17deb287d5a11fb817f || >=dc99f600698dcac69b8f56dda9a8a00d645c5ffc <a885387dae7986a55bae5c77a15bdd447f64e9b9 || >=dc99f600698dcac69b8f56dda9a8a00d645c5ffc <50aff80475abd3533eef4320477037e6fcc6b56e | acb40ebfa5c4d62f84339fcbf713f2a9fd033a71, c820f4b7f2fa38f8769db0d0cefdd94e2721504d, 4628efbdc7affd094181f5263e65c1062e31f15f, 80ec024d53a05c60ad1d08968dcf745f10c1665c, 0a052e0808e015e68144a9877e6ef42b952c49fa, 1bc55c29cd85818e9052f17deb287d5a11fb817f, a885387dae7986a55bae5c77a15bdd447f64e9b9, 50aff80475abd3533eef4320477037e6fcc6b56e |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: net/packet: avoid fanout hook re-registration after unregister packet_set_ring() temporarily detaches a socket from packet delivery while reconfiguring its ring. It records the previous running state, clears po->num, unregisters the protocol hook when needed, drops po->bind_lock, and later restores po->num and re-registers the hook from the saved was_running value. That unlocked window can race with NETDEV_UNREGISTER. The notifier can observe the socket as not running, skip __unregister_prot_hook(), and invalidate the per-socket binding by setting po->ifindex to -1 and clearing po->prot_hook.dev. A one-member fanout group can still retain its shared fanout hook device pointer. When packet_set_ring() resumes, re-registering solely from the stale was_running state can re-add the fanout hook after the device has been unregistered. Treat po->ifindex == -1 as an invalidated binding after reacquiring po->bind_lock. This is distinct from ifindex 0, the normal unbound/wildcard state: ifindex -1 marks an existing device binding that was invalidated when the device was unregistered. Restore po->num as before, but do not re-register the hook if device unregister already detached the socket.
Quoted source text, attributed separately from HOL analysis.