Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-68302

In the Linux kernel, the following vulnerability has been resolved: amt: re-read skb header pointers after every pull Several AMT receive and transmit paths cache a pointer into the skb head (ip_hdr...
Back to all
CVE

DEBIAN-CVE-2026-68302

In the Linux kernel, the following vulnerability has been resolved: amt: re-read skb header pointers after every pull Several AMT receive and transmit paths cache a pointer into the skb head (ip_hdr...

In the Linux kernel, the following vulnerability has been resolved:  amt: re-read skb header pointers after every pull  Several AMT receive and transmit paths cache a pointer into the skb head (iphdr(), ipv6hdr(), ethhdr() or the AMT message header) and then call a helper that can reallocate that head before the cached pointer is used again.  pskbmaypull(), ipmcmaypull(), ipv6mcmaypull(), iptunnelpullheader(), ipmccheckigmp() and ipv6mccheckmld() can all free the old head and move the data, so a pointer taken before the call dangles afterwards and the later access is a use-after-free of the freed head.  The affected sites are:    amtrcv() caches iphdr() before amtparsetype() pulls, then reads   iph->saddr.    amtdevxmit() caches iphdr()/ipv6hdr() before ipmccheckigmp()/   ipv6mccheckmld() and pskbmaypull(), then reads the group address.    amtmulticastdatahandler() caches ethhdr() before pskbmaypull(),   then writes the L2 header.    amtmembershipqueryhandler() caches the AMT header, the outer and   inner ethhdr() and iphdr() before iptunnelpullheader() and several   pulls, then reads and writes them.    amtigmpv3reporthandler() and amtmldv2reporthandler() cache   iphdr()/ipv6hdr() and the current group record and read the record   count from the report header inside the record loop, across the   *mcmaypull() calls.    amtupdatehandler() caches iphdr() and the AMT membership-update   header before pskbmaypull(), iptunnelpullheader(),   ipmccheckigmp() and the report handler, then reads iph->daddr and   amtmu->nonce / amtmu->responsemac.  Fix each site by either snapshotting the scalar that is used after the pull before the first pull runs, or re-deriving the header pointer from the skb after the last pull that can move the head.  Values that are stable across the pull (source and group address, the response MAC and nonce, the record count, the outer source MAC) are snapshotted; pointers that are written through or read repeatedly are re-derived.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-68302

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
6.1.187-1,6.12.101-1,7.1.6-1,6.12.101-1~deb12u1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading