Answer in brief
CVE-2026-68354 records a Unknown severity vulnerability in firewire: net: Fix fragmented datagram reassembly. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c76acec6d55107b652a37c90b36c00bc8b04dabb <b7d633c7c92321be98724b1d365e8ce507f2f349 || >=c76acec6d55107b652a37c90b36c00bc8b04dabb <22e05b8ddbcf7d22c7f1598786e86635547e554d || >=c76acec6d55107b652a37c90b36c00bc8b04dabb <0177e578d7a885037b0fb82286c12e9d0360cc10 || >=c76acec6d55107b652a37c90b36c00bc8b04dabb <2a5aa4e9b89227d1a1690fb8d5b81e5f3b261999 || >=c76acec6d55107b652a37c90b36c00bc8b04dabb <d52a13adbb8ccbab99cd3bad36804e87d8b5c052 | b7d633c7c92321be98724b1d365e8ce507f2f349, 22e05b8ddbcf7d22c7f1598786e86635547e554d, 0177e578d7a885037b0fb82286c12e9d0360cc10, 2a5aa4e9b89227d1a1690fb8d5b81e5f3b261999, d52a13adbb8ccbab99cd3bad36804e87d8b5c052 |
| Linux/Linuxgeneric | 2.6.31 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: firewire: net: Fix fragmented datagram reassembly fwnet_frag_new() keeps a sorted list of received fragments for a partial datagram. When a new fragment is adjacent to an existing fragment, the code checks whether the new fragment also closes the gap to the next or previous list entry. Those neighbor lookups currently assume that the current fragment always has a real next or previous fragment. At a list edge, the next or previous entry is the list head, not a struct fwnet_fragment_info. The gap checks also compare against the old edge of the current fragment instead of the edge after adding the new fragment. As a result, a fragment that bridges two existing ranges may leave two adjacent ranges unmerged, so fwnet_pd_is_complete() can miss a complete datagram. Check for the list head before looking up the neighboring fragment, and compare the neighbor against the new fragment's far edge when deciding whether to merge all three ranges. This issue was found by a static analysis checker and confirmed by manual source review.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68354 records a Unknown severity vulnerability in firewire: net: Fix fragmented datagram reassembly. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c76acec6d55107b652a37c90b36c00bc8b04dabb <b7d633c7c92321be98724b1d365e8ce507f2f349 || >=c76acec6d55107b652a37c90b36c00bc8b04dabb <22e05b8ddbcf7d22c7f1598786e86635547e554d || >=c76acec6d55107b652a37c90b36c00bc8b04dabb <0177e578d7a885037b0fb82286c12e9d0360cc10 || >=c76acec6d55107b652a37c90b36c00bc8b04dabb <2a5aa4e9b89227d1a1690fb8d5b81e5f3b261999 || >=c76acec6d55107b652a37c90b36c00bc8b04dabb <d52a13adbb8ccbab99cd3bad36804e87d8b5c052 | b7d633c7c92321be98724b1d365e8ce507f2f349, 22e05b8ddbcf7d22c7f1598786e86635547e554d, 0177e578d7a885037b0fb82286c12e9d0360cc10, 2a5aa4e9b89227d1a1690fb8d5b81e5f3b261999, d52a13adbb8ccbab99cd3bad36804e87d8b5c052 |
| Linux/Linuxgeneric | 2.6.31 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: firewire: net: Fix fragmented datagram reassembly fwnet_frag_new() keeps a sorted list of received fragments for a partial datagram. When a new fragment is adjacent to an existing fragment, the code checks whether the new fragment also closes the gap to the next or previous list entry. Those neighbor lookups currently assume that the current fragment always has a real next or previous fragment. At a list edge, the next or previous entry is the list head, not a struct fwnet_fragment_info. The gap checks also compare against the old edge of the current fragment instead of the edge after adding the new fragment. As a result, a fragment that bridges two existing ranges may leave two adjacent ranges unmerged, so fwnet_pd_is_complete() can miss a complete datagram. Check for the list head before looking up the neighboring fragment, and compare the neighbor against the new fragment's far edge when deciding whether to merge all three ranges. This issue was found by a static analysis checker and confirmed by manual source review.
Quoted source text, attributed separately from HOL analysis.