CVE-2026-68302: amt: re-read skb header pointers after every pull

Published Aug 10, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

amt: re-read skb header pointers after every pull

Several AMT receive and transmit paths cache a pointer into the skb head (iphdr(), ipv6hdr(), ethhdr() or the AMT message header) and then call a helper that can reallocate that head before the cached pointer is used again. pskbmaypull(), ipmcmaypull(), ipv6mcmaypull(), iptunnelpullheader(), ipmccheckigmp() and ipv6mccheckmld() can all free the old head and move the data, so a pointer taken before the call dangles afterwards and the later access is a use-after-free of the freed head.

The affected sites are:

amtrcv() caches iphdr() before amtparsetype() pulls, then reads iph->saddr.

amtdevxmit() caches iphdr()/ipv6hdr() before ipmccheckigmp()/ ipv6mccheckmld() and pskbmaypull(), then reads the group address.

amtmulticastdatahandler() caches ethhdr() before pskbmaypull(), then writes the L2 header.

amtmembershipqueryhandler() caches the AMT header, the outer and inner ethhdr() and iphdr() before iptunnelpullheader() and several pulls, then reads and writes them.

amtigmpv3reporthandler() and amtmldv2reporthandler() cache iphdr()/ipv6hdr() and the current group record and read the record count from the report header inside the record loop, across the mcmaypull() calls.

amtupdatehandler() caches iphdr() and the AMT membership-update header before pskbmaypull(), iptunnelpullheader(), ipmccheckigmp() and the report handler, then reads iph->daddr and amtmu->nonce / amtmu->responsemac.

Fix each site by either snapshotting the scalar that is used after the pull before the first pull runs, or re-deriving the header pointer from the skb after the last pull that can move the head. Values that are stable across the pull (source and group address, the response MAC and nonce, the record count, the outer source MAC) are snapshotted; pointers that are written through or read repeatedly are re-derived.

Affected Software

1 affected component
Linux Linux kernel

Event History

Aug 10, 2026
CVE Published
via MITRE·12:02 PM
Data Sourced
via MITRE·12:02 PM
Description
Data Sourced
via NVD·01:20 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-68302?

The severity of CVE-2026-68302 is rated as 55.

2

How do I fix CVE-2026-68302?

To fix CVE-2026-68302, update the Linux kernel to the latest version where the vulnerability has been resolved.

3

What systems are affected by CVE-2026-68302?

CVE-2026-68302 affects systems running the Linux kernel.

4

What type of vulnerability is CVE-2026-68302?

CVE-2026-68302 is categorized as a Use After Free vulnerability.

5

Is CVE-2026-68302 exploitable remotely?

The details do not indicate that CVE-2026-68302 is remotely exploitable, but it still poses a risk to affected systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203