From: Dong Chenchen <dongchenchen2@huawei.com> CVE: CVE-2026-68426 Reference: https://atomgit.com/src-openeuler/kernel/issues/17032 This series fixes CVE-2026-68426, a use-after-free in validate_xmit_xfrm(): when async crypto steals GSO segments (->xmit() returns -EINPROGRESS), the returned segment list head keeps skb->prev pointing at a stolen (crypto-owned) segment. validate_xmit_skb_list() later does tail = skb->prev and tail->next = skb, writing through the stale pointer. Patch 1 is a prerequisite backport of upstream d1d17a359ce6 ("esp: remove the skb from the chain when it's enqueued in cryptd_wq", v5.6). It introduces the pskb tracking of the last retained segment and properly unlinks stolen segments from the chain. Without it the CVE fix commit cannot be applied faithfully: its skb->prev repoint logic builds directly on the pskb variable and the unlinking behaviour introduced there. Patch 2 is the mainline fix for CVE-2026-68426, 3f4c3919baf0944ad96580467c302bc6c7758b00 (v7.2-rc4): repoint skb->prev at the last retained segment before returning, so validate_xmit_skb_list() never chains onto a segment now owned by the crypto engine. Both patches are adapted to the 4.19-based openEuler-1.0-LTS code base, which still uses the original do-while loop form of validate_xmit_xfrm() (the upstream skb_list_walk_safe refactor c3b18e0d9254 is a pure refactor and is not backported). The target's "return skb" semantics are kept (upstream's ERR_PTR(-EINPROGRESS) return comes from the unrelated later commit 6860b467f569 and is not needed for this fix). Note: this series is based on f702ec806ef8 and supersedes the incomplete single-commit adaptation 0026e6ba24b0 ("xfrm: fix stale skb->prev after async crypto steals a GSO segment"), which tracked pskb without the prerequisite chain-unlink fix. Petr Wozniak (1): xfrm: fix stale skb->prev after async crypto steals a GSO segment Xin Long (1): esp: remove the skb from the chain when it's enqueued in cryptd_wq net/xfrm/xfrm_device.c | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) -- 2.43.0