CVE-2026-68296: net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
In the Linux kernel, the following vulnerability has been resolved:
net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
Before commit 00d066a4d4ed ("netdevfeatures: convert NETIFFLLTX to dev->lltx"), NETIFFLLTX was set unconditionally in both gretunnelinit() and ip6gretnlinitfeatures() alongside GREFEATURES:
dev->features |= GREFEATURES | NETIFFLLTX;
When that commit converted NETIFFLLTX to the dev->lltx flag, it placed 'dev->lltx = true' after the SEQ/CSUM early returns instead of before them. This causes GRE/GRETAP/ip6gre tunnels with SEQ or CSUM+encap to lose lockless TX, reintroducing xmitlock acquisition around their ndostartxmit. Since GRE xmit re-enters the stack via iptunnelxmit(), holding xmitlock risks ABBA deadlock with the underlay device.
CPU0 CPU1 ---- ---- lock(&qdiscxmitlockkey#6); lock(&qdiscxmitlockkey#3); lock(&qdiscxmitlockkey#6); lock(&qdiscxmitlockkey#3);
Fix by moving dev->lltx = true before the early returns in both functions, restoring the original unconditional behavior.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68296?
The severity rating of CVE-2026-68296 is 34, indicating a moderate risk.
How do I fix CVE-2026-68296?
To resolve CVE-2026-68296, ensure that you update your Linux kernel to a version that includes the fix.
What systems are affected by CVE-2026-68296?
CVE-2026-68296 affects the Linux kernel, specifically regarding GRE tunnels with SEQ/CSUM.
Is CVE-2026-68296 a local or remote vulnerability?
CVE-2026-68296 is considered a local vulnerability, as it requires access to the affected system.
What is the impact of CVE-2026-68296?
The impact of CVE-2026-68296 could potentially lead to issues with GRE tunnel functionality if not patched.