Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-68425— IB/mad: Drop unmatched RMPP responses before reassembly

CVSS 7.1 · High EPSS 0.26% · P17

Possible ATT&CK Techniques 2AI

T1043 T1498 · Network Denial of Service

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinuxfa619a77046bef30478697aba0553991033afb8e< dfa535c94406c03d3f0c869ef3ba5528e395737caffected
fa619a77046bef30478697aba0553991033afb8e< 6e1bd7f590b0ccfee07f7fe1d48b92059bd37d72affected
fa619a77046bef30478697aba0553991033afb8e< 98d2d468b4faa1fdc68c0c6c238389906ee3490caffected
fa619a77046bef30478697aba0553991033afb8e< ad9c9ad3204f63a46f0f7de29687a8e512f05e29affected
fa619a77046bef30478697aba0553991033afb8e< d2e52d610b9b09694261632340b801a421e0b0c5affected
2.6.13affected
< 2.6.13unaffected
6.6.148≤ 6.6.*unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-68425

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
IB/mad: Drop unmatched RMPP responses before reassembly
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before reassembly Kernel-handled RMPP receive processing starts reassembly for active DATA responses before the response is matched to an outstanding send. The normal match happens later, after ib_process_rmpp_recv_wc() has either assembled a complete message or consumed the segment. That ordering lets an unsolicited response that routes to a kernel RMPP agent by the high TID bits allocate or extend RMPP receive state before the full TID and source address are checked against a real request. A reordered burst can therefore reach the receive-side insertion path even though the response would not match any send. For kernel-handled RMPP DATA responses, require the existing ib_find_send_mad() match before entering RMPP reassembly. The matcher already checks the full TID, management class and source address/GID against the agent wait, backlog and in-flight send lists. If there is no match, drop the response without creating RMPP state. This leaves the RMPP window behavior unchanged and only rejects responses that have no corresponding request.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于RMPP响应处理顺序不当,在匹配发送之前即启动重组,可能导致未匹配的响应分配或扩展RMPP接收状态。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux fa619a77046bef30478697aba0553991033afb8e ~ dfa535c94406c03d3f0c869ef3ba5528e395737c -
LinuxLinux 2.6.13 -

II. Public POCs for CVE-2026-68425

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-68425

登录查看更多情报信息。

Patches & Fixes for CVE-2026-68425 (5)

Same Patch Batch · Linux · 2026-08-10 · 345 CVEs total

CVE-2026-683889.8 CRITICALsmb/client: handle overlapping allocated ranges in fallocate
CVE-2026-681379.8 CRITICALnet/x25: fix use-after-free in x25_kill_by_neigh()
CVE-2026-681369.8 CRITICALnet: gro: fix double aggregation of flush-marked skbs
CVE-2026-681449.8 CRITICALphonet: pep: fix use-after-free in pep_get_sb()
CVE-2026-681549.8 CRITICALlibceph: reject zero bucket types in crush_decode
CVE-2026-681569.8 CRITICALlibceph: refresh auth->authorizer_buf{,_len} after authorizer update
CVE-2026-681279.8 CRITICALila: reload IPv6 header after pskb_may_pull in checksum adjust
CVE-2026-681589.8 CRITICALlibceph: Fix multiplication overflow in decode_new_up_state_weight()
CVE-2026-681239.8 CRITICALopenvswitch: fix GSO userspace truncation underflow
CVE-2026-681599.8 CRITICALlibceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
CVE-2026-681609.8 CRITICALceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
CVE-2026-681619.8 CRITICALsctp: close UDP tunnel sockets during netns teardown
CVE-2026-681179.8 CRITICALtipc: clear sock->sk on the failed-insert path in tipc_sk_create()
CVE-2026-681709.8 CRITICALmptcp: fix stale skb->sk reference on subflow close
CVE-2026-683009.8 CRITICALsctp: auth: verify auth requirement when auth_chunk is NULL
CVE-2026-683859.8 CRITICALs390/checksum: Fix csum_partial() without vector facility
CVE-2026-683819.8 CRITICALksmbd: pin conn during async oplock break notification
CVE-2026-683029.8 CRITICALamt: re-read skb header pointers after every pull
CVE-2026-684269.8 CRITICALxfrm: fix stale skb->prev after async crypto steals a GSO segment
CVE-2026-681249.6 CRITICALmctp: serial: handle zero-length frames to prevent rx buffer overflow

Showing top 20 of 345 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-68425

No comments yet


Leave a comment