-
CVE-2026-80838
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:54:48
- Zuletzt bearbeitet 04.09.2026 16:18:12
- Erkennungen
vxlan: keep the last remote linked during FDB flush
In the Linux kernel, the following vulnerability has been resolved: vxlan: keep the last remote linked during FDB flush A non-nexthop FDB entry is expected to have at least one remote while it remains reachable through the FDB hash table. A filtered bulk flush violates this invariant when every remote matches: It unlinks the last remote in vxlan_fdb_dst_destroy() and only afterwards tells vxlan_flush() to destroy the parent FDB entry. An RCU reader can find the parent during this interval. first_remote_rcu() then applies list_entry_rcu() to the empty list head, producing an invalid remote pointer that the receive learning path can read from and write to. When a matching remote is the sole remaining remote, leave it linked and ask the caller to destroy the entire FDB entry. vxlan_fdb_destroy() keeps the remote attached while sending the deletion notification and removing the parent from the lookup structures.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f
Version <
2a7c2f00843225d5f037676bca649321f3d024c7
Status
affected
Version
c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f
Version <
a8820c8a7718327e96849782033e7c85a0f6bcfe
Status
affected
Version
c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f
Version <
8ba68fd6cdd1e3c92b92f25c7e48bf7bd51a183c
Status
affected
Version
c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f
Version <
4bbc76ee1b21d3bd045d6d819b2bacd30a6372ab
Status
affected
Version
c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f
Version <
d5d4a7b538b52db63927773a8905fcd9f78a42e2
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.7
Status
affected
Version
0
Version <
6.7
Status
unaffected
Version <=
6.12.*
Version
6.12.108
Status
unaffected
Version <=
6.18.*
Version
6.18.49
Status
unaffected
Version <=
7.1.*
Version
7.1.13
Status
unaffected
Version <=
7.2.*
Version
7.2.3
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.063 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/2a7c2f00843225d5f037676bca649321f3d024c7
https://git.kernel.org/stable/c/a8820c8a7718327e96849782033e7c85a0f6bcfe
https://git.kernel.org/stable/c/8ba68fd6cdd1e3c92b92f25c7e48bf7bd51a183c
https://git.kernel.org/stable/c/4bbc76ee1b21d3bd045d6d819b2bacd30a6372ab
https://git.kernel.org/stable/c/d5d4a7b538b52db63927773a8905fcd9f78a42e2