CVE-2026-68116
In the Linux kernel, the following vulnerability has been resolved:
vxlan: mdb: Fix source list corruption on a failed replace
When replacing the source list of an MDB remote entry, all existing sources are first marked for deletion and vxlan_mdb_remote_srcs_add() is then called to add the new source list. Sources present in the new list have their deletion mark cleared, and any sources left marked afterwards are removed.
If vxlan_mdb_remote_srcs_add() fails partway through, its error path deletes all entries on the remote's source list.
Leer descripción completaMostrar menos
That rollback is only correct for its other caller, vxlan_mdb_remote_add(), where the remote was just allocated and the list contains solely entries added during the call. On the replace path the list also holds pre-existing sources, so a failed replace tears them down together with their (S, G) forwarding entries instead of leaving the entry unchanged.
This is reachable from an existing (*, G) remote. An EXCLUDE filter that loses sources starts forwarding traffic that should be blocked, while an INCLUDE filter that loses sources drops traffic that should be forwarded.
Mark entries created during the current pass with a new VXLAN_SGRP_F_NEW flag. On failure, delete only those entries and clear the deletion mark on the pre-existing ones, so a failed replace leaves the source list untouched. Retain the flag until the whole operation succeeds and then clear it. Also stop vxlan_mdb_remote_src_add() from deleting a pre-existing entry it only looked up when adding that entry's forwarding entry fails.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
- Puntuación base: 7.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.12%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Impacto principal
T1565.001Stored Data Manipulationimpact65 % - Impacto secundario
T1499.004Application or System Exploitationimpact60 %
Vulnerabilidad local de escalada de privilegios (AV:L, PR:L) en kernel Linux que corrompe listas de origen MDB en VXLAN, permitiendo manipular filtros EXCLUDE/INCLUDE para desviar o bloquear tráfico de red.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/2c54dff57606590fa4abec46bab6bea3133f1539
- https://git.kernel.org/stable/c/54a3c27b357dfb34f327f89bfadeb998bef8051e
- https://git.kernel.org/stable/c/5bc8fc1d2ff802eec839e03adef5df597421898d
- https://git.kernel.org/stable/c/79370b573e92e8f190eb5f9a511fa5398340d8b2
- https://git.kernel.org/stable/c/dcd9b465965422b9654f6026e8a2fa8984f74c3c
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-68116",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.9,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 5.3,
"exploitabilityScore": 2
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "5bc8fc1d2ff802eec839e03adef5df597421898d",
"versionType": "git"
},
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "2c54dff57606590fa4abec46bab6bea3133f1539",
"versionType": "git"
},
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "79370b573e92e8f190eb5f9a511fa5398340d8b2",
"versionType": "git"
},
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "54a3c27b357dfb34f327f89bfadeb998bef8051e",
"versionType": "git"
},
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "dcd9b465965422b9654f6026e8a2fa8984f74c3c",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/vxlan/vxlan_mdb.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.4",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/vxlan/vxlan_mdb.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-10T13:19:56.560",
"references": [
{
"url": "https://git.kernel.org/stable/c/2c54dff57606590fa4abec46bab6bea3133f1539",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/54a3c27b357dfb34f327f89bfadeb998bef8051e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5bc8fc1d2ff802eec839e03adef5df597421898d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/79370b573e92e8f190eb5f9a511fa5398340d8b2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dcd9b465965422b9654f6026e8a2fa8984f74c3c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: mdb: Fix source list corruption on a failed replace\n\nWhen replacing the source list of an MDB remote entry, all existing\nsources are first marked for deletion and vxlan_mdb_remote_srcs_add()\nis then called to add the new source list. Sources present in the new\nlist have their deletion mark cleared, and any sources left marked\nafterwards are removed.\n\nIf vxlan_mdb_remote_srcs_add() fails partway through, its error path\ndeletes all entries on the remote's source list. That rollback is only\ncorrect for its other caller, vxlan_mdb_remote_add(), where the remote\nwas just allocated and the list contains solely entries added during\nthe call. On the replace path the list also holds pre-existing sources,\nso a failed replace tears them down together with their (S, G)\nforwarding entries instead of leaving the entry unchanged.\n\nThis is reachable from an existing (*, G) remote. An EXCLUDE filter\nthat loses sources starts forwarding traffic that should be blocked,\nwhile an INCLUDE filter that loses sources drops traffic that should be\nforwarded.\n\nMark entries created during the current pass with a new\nVXLAN_SGRP_F_NEW flag. On failure, delete only those entries and clear\nthe deletion mark on the pre-existing ones, so a failed replace leaves\nthe source list untouched. Retain the flag until the whole operation\nsucceeds and then clear it. Also stop vxlan_mdb_remote_src_add() from\ndeleting a pre-existing entry it only looked up when adding that\nentry's forwarding entry fails."
}
],
"lastModified": "2026-08-17T05:18:11.023",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}