Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-68144

In the Linux kernel, the following vulnerability has been resolved: phonet: pep: fix use-after-free in pep_get_sb() pep_get_sb() doesn't consider that pskb_may_pull() might have relocated the skb da...
Back to all
CVE

DEBIAN-CVE-2026-68144

In the Linux kernel, the following vulnerability has been resolved: phonet: pep: fix use-after-free in pep_get_sb() pep_get_sb() doesn't consider that pskb_may_pull() might have relocated the skb da...

In the Linux kernel, the following vulnerability has been resolved:  phonet: pep: fix use-after-free in pepgetsb()  pepgetsb() doesn't consider that pskbmaypull() might have relocated the skb data, and continue to access the older pointer, causing UAF.  Reproduced under KASAN:    BUG: KASAN: slab-use-after-free in pepgetsb+0x234/0x3b0   Read of size 1 at addr ff11000105510f50 by task repro/157    pepgetsb+0x234/0x3b0    pipehandlerdorcv+0x5f7/0xa10    pepdorcv+0x203/0x410    skreceiveskb+0x471/0x4a0    phonetrcv+0x5b3/0x6c0    _netifreceiveskb+0xcc/0x1d0  Refetch the header with skbheaderpointer() after pskbmay_pull(), so the possibly stale pointer is no longer dereferenced. There are better ways to solve this, but, this is the less instrusive one.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-68144

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
6.1.187-1,6.12.101-1,7.1.6-1,6.12.101-1~deb12u1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading