-

CVE-2026-80838

vxlan: keep the last remote linked during FDB flush

In the Linux kernel, the following vulnerability has been resolved:

vxlan: keep the last remote linked during FDB flush

A non-nexthop FDB entry is expected to have at least one remote while it
remains reachable through the FDB hash table. A filtered bulk flush
violates this invariant when every remote matches: It unlinks the last
remote in vxlan_fdb_dst_destroy() and only afterwards tells vxlan_flush()
to destroy the parent FDB entry.

An RCU reader can find the parent during this interval.
first_remote_rcu() then applies list_entry_rcu() to the empty list head,
producing an invalid remote pointer that the receive learning path can
read from and write to.

When a matching remote is the sole remaining remote, leave it linked and
ask the caller to destroy the entire FDB entry. vxlan_fdb_destroy() keeps
the remote attached while sending the deletion notification and removing
the parent from the lookup structures.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f
Version < 2a7c2f00843225d5f037676bca649321f3d024c7
Status affected
Version c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f
Version < a8820c8a7718327e96849782033e7c85a0f6bcfe
Status affected
Version c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f
Version < 8ba68fd6cdd1e3c92b92f25c7e48bf7bd51a183c
Status affected
Version c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f
Version < 4bbc76ee1b21d3bd045d6d819b2bacd30a6372ab
Status affected
Version c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f
Version < d5d4a7b538b52db63927773a8905fcd9f78a42e2
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.7
Status affected
Version 0
Version < 6.7
Status unaffected
Version <= 6.12.*
Version 6.12.108
Status unaffected
Version <= 6.18.*
Version 6.18.49
Status unaffected
Version <= 7.1.*
Version 7.1.13
Status unaffected
Version <= 7.2.*
Version 7.2.3
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2a7c2f00843225d5f037676bca649321f3d024c7
https://git.kernel.org/stable/c/a8820c8a7718327e96849782033e7c85a0f6bcfe
https://git.kernel.org/stable/c/8ba68fd6cdd1e3c92b92f25c7e48bf7bd51a183c
https://git.kernel.org/stable/c/4bbc76ee1b21d3bd045d6d819b2bacd30a6372ab
https://git.kernel.org/stable/c/d5d4a7b538b52db63927773a8905fcd9f78a42e2