Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-68441

Published Aug 12, 2026 EPSS 0.15% (4th pctl)

Overview

CVE-2026-68441 is a known-severity vulnerability. It was published on August 12, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains

When a TC filter attached to a qdisc filter chain returns

TC_ACT_REDIRECT (ex: via an eBPF program calling bpf_redirect() or an

act_bpf action), the redirect was silently lost i.e no qdisc classify

function handled TC_ACT_REDIRECT, so the packet fell through the

switch and was enqueued normally instead of being redirected.

This has been broken since bpf_redirect() was introduced for TC in

commit 27b29f63058d ("bpf: add bpf_redirect() helper"). We got lucky

for a long time because bpf_net_context was a per-CPU variable that

was always available.

commit 401cb7dae813 ("net: Reference bpf_redirect_info via task_struct

on PREEMPT_RT.") turned bpf_net_context into a task_struct member that

is only set up by explicit callers. Without a caller setting it up,

bpf_redirect() itself crashes with a NULL pointer dereference in

bpf_net_ctx_get_ri(). However, even with bp

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-68441?

CVE-2026-68441 is a known-severity vulnerability. It was published on August 12, 2026.

How severe is CVE-2026-68441?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-68441?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-68441?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-68441 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.