SB20260812405 - Resource exhaustion in Linux kernel google gve driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2026-68129)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource handling in the gve Rx queue handling logic when processing received packets under extreme memory pressure. A local user can trigger page allocation failures that leave too few descriptors posted to hardware to cause a denial of service.
The issue can result in a permanent Rx queue stall because no receive completions are generated, preventing NAPI from being scheduled again.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0c317349b4baa5038d1fc373bf46d5a2419d1710
- https://git.kernel.org/stable/c/299d5728a7312fdd02059b074aebbe4ebbd391e4
- https://git.kernel.org/stable/c/689b9f588d2d7323dc66293fe594a68d030f400f
- https://git.kernel.org/stable/c/91e0249f3ef62b75fe8c9c9372eaba32876e4b3a
- https://git.kernel.org/stable/c/b65352a1bac64442ad95e64f385b40ccb9f1b0db