---
id: CVE-2026-68288
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD

  net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code
  the NET_DM_ATTR_PAYLOAD attribute to a…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD

  net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code
  the NET_DM_ATTR_PAYLOAD attribute to a…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f <
    05173de42a9923a3eaadebcb0dd5bc83ffba174c
  - >-
    Linux >= ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f <
    89178ffe5bddc99c057ba2768db1f8d9c5e1408c
  - >-
    Linux >= ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f <
    8fd6975d2aecc36b25ee82b6aef88e62a3527ccb
  - >-
    Linux >= ca30707dee2bc8bc81cfd8b4277fe90f7ca6df1f <
    5e9c8baee0329fbefe7c67aea945e2a07f15e98b
  - Linux 5.4
published: '2026-08-10'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T14:17:16.467'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-68288'
references:
  - url: 'https://git.kernel.org/stable/c/05173de42a9923a3eaadebcb0dd5bc83ffba174c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5e9c8baee0329fbefe7c67aea945e2a07f15e98b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/89178ffe5bddc99c057ba2768db1f8d9c5e1408c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8fd6975d2aecc36b25ee82b6aef88e62a3527ccb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00209
epssPercentile: 0.09809
ingestedAt: '2026-09-21T13:37:22.845Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD

net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code
the NET_DM_ATTR_PAYLOAD attribute to avoid zeroing the packet payload
before overwriting it with skb_copy_bits().

skb_put() reserves nla_total_size(payload_len), i.e. the header plus the
NLA_ALIGN() padding, but only payload_len bytes are copied in. When
payload_len is not a multiple of 4 the 1-3 padding bytes are never
initialized and are leaked to user space inside the netlink message.

KMSAN confirms the leak for the software path when the packet payload
length is not 4-byte aligned:

  BUG: KMSAN: kernel-infoleak in _copy_to_iter
   _copy_to_iter
   __skb_datagram_iter
   skb_copy_datagram_iter
   netlink_recvmsg
   sock_recvmsg
   __sys_recvfrom
  Uninit was created at:
   kmem_cache_alloc_node_noprof
   __alloc_skb
   net_dm_packet_work
  Bytes 173-175 of 176 are uninitialized

Use __nla_reserve(), which sets up the attribute header and zeroes the
padding, instead of open coding the attribute construction.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
