Re: Linux 5.10.268

From: Greg Kroah-Hartman

Date: Fri Aug 28 2026 - 02:57:49 EST


diff --git a/Makefile b/Makefile
index 3e1b204d5291..0aadd120b6f6 100644
--- a/Makefile
+++ b/Makefile
@@ -1,7 +1,7 @@
# SPDX-License-Identifier: GPL-2.0
VERSION = 5
PATCHLEVEL = 10
-SUBLEVEL = 267
+SUBLEVEL = 268
EXTRAVERSION =
NAME = Dare mighty things

diff --git a/net/ipv4/inet_fragment.c b/net/ipv4/inet_fragment.c
index 016b224a17e5..18217537cb29 100644
--- a/net/ipv4/inet_fragment.c
+++ b/net/ipv4/inet_fragment.c
@@ -353,6 +353,13 @@ int inet_frag_queue_insert(struct inet_frag_queue *q, struct sk_buff *skb,
{
struct sk_buff *last = q->fragments_tail;

+ /* An IP fragment is never a GSO packet, but an untrusted source
+ * (virtio_net_hdr) may have attached GSO metadata to it. Do not let
+ * that reach the reassembled skb, whose head keeps the first
+ * fragment's shinfo and whose frag_list is not GRO-shaped.
+ */
+ skb_gso_reset(skb);
+
/* RFC5722, Section 4, amended by Errata ID : 3089
* When reassembling an IPv6 datagram, if
* one or more its constituent fragments is determined to be an