Incorrect Calculation of Buffer Size in Linux kernel - CVE-2026-68287
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper calculation of buffer size in net/core/drop_monitor.c when handling 64-bit drop monitor attributes on affected architectures. A local user can trigger packet report generation to cause a denial of service.
This affects 32-bit architectures without CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS because 64-bit netlink attributes may require additional padding for alignment.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-68287
linux (Debian package) - update to 6.12.111-1