CVE-2026-68385 is a vulnerability in Linux Kernel
Published on August 10, 2026
s390/checksum: Fix csum_partial() without vector facility
In the Linux kernel, the following vulnerability has been resolved:
s390/checksum: Fix csum_partial() without vector facility
Currently csum_partial() calls csum_copy() with copy=false and dst=NULL.
On machines without the vector facility, csum_copy() falls back to
cksm(dst, ...), causing the checksum to be calculated from address zero
instead of the source buffer.
The VX implementation already checksums data loaded from src. Make the
fallback do the same by passing src to cksm().
Products Associated with CVE-2026-68385
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version dcd3e1de9d17dc43dfed87a9fc814b9dec508043 and below 5fc0a2a6eeb99cac991242bb48796c7749ce3261 is affected.
- Version dcd3e1de9d17dc43dfed87a9fc814b9dec508043 and below 1d9a2f01b3c4e5c88e06b2db4b5460c2ec884722 is affected.
- Version dcd3e1de9d17dc43dfed87a9fc814b9dec508043 and below 898bb2814f38399108bdd2113f38d97383a7036a is affected.
- Version dcd3e1de9d17dc43dfed87a9fc814b9dec508043 and below 4bb06b60d982355e22647b3d12d6619419f8c1fa is affected.
- Version 6.9 is affected.
- Before 6.9 is unaffected.
- Version 6.12.101, <= 6.12.* is unaffected.
- Version 6.18.42, <= 6.18.* is unaffected.
- Version 7.1.6, <= 7.1.* is unaffected.
- Version 7.2-rc4, <= * is unaffected.