CVE-2026-68302: amt: re-read skb header pointers after every pull
In the Linux kernel, the following vulnerability has been resolved:
amt: re-read skb header pointers after every pull
Several AMT receive and transmit paths cache a pointer into the skb head (iphdr(), ipv6hdr(), ethhdr() or the AMT message header) and then call a helper that can reallocate that head before the cached pointer is used again. pskbmaypull(), ipmcmaypull(), ipv6mcmaypull(), iptunnelpullheader(), ipmccheckigmp() and ipv6mccheckmld() can all free the old head and move the data, so a pointer taken before the call dangles afterwards and the later access is a use-after-free of the freed head.
The affected sites are:
amtrcv() caches iphdr() before amtparsetype() pulls, then reads iph->saddr.
amtdevxmit() caches iphdr()/ipv6hdr() before ipmccheckigmp()/ ipv6mccheckmld() and pskbmaypull(), then reads the group address.
amtmulticastdatahandler() caches ethhdr() before pskbmaypull(), then writes the L2 header.
amtmembershipqueryhandler() caches the AMT header, the outer and inner ethhdr() and iphdr() before iptunnelpullheader() and several pulls, then reads and writes them.
amtigmpv3reporthandler() and amtmldv2reporthandler() cache iphdr()/ipv6hdr() and the current group record and read the record count from the report header inside the record loop, across the mcmaypull() calls.
amtupdatehandler() caches iphdr() and the AMT membership-update header before pskbmaypull(), iptunnelpullheader(), ipmccheckigmp() and the report handler, then reads iph->daddr and amtmu->nonce / amtmu->responsemac.
Fix each site by either snapshotting the scalar that is used after the pull before the first pull runs, or re-deriving the header pointer from the skb after the last pull that can move the head. Values that are stable across the pull (source and group address, the response MAC and nonce, the record count, the outer source MAC) are snapshotted; pointers that are written through or read repeatedly are re-derived.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68302?
The severity of CVE-2026-68302 is rated as 55.
How do I fix CVE-2026-68302?
To fix CVE-2026-68302, update the Linux kernel to the latest version where the vulnerability has been resolved.
What systems are affected by CVE-2026-68302?
CVE-2026-68302 affects systems running the Linux kernel.
What type of vulnerability is CVE-2026-68302?
CVE-2026-68302 is categorized as a Use After Free vulnerability.
Is CVE-2026-68302 exploitable remotely?
The details do not indicate that CVE-2026-68302 is remotely exploitable, but it still poses a risk to affected systems.