CVE-2026-93250
In the Linux kernel, the following vulnerability has been resolved:
vxlan: mdb: Fix use-after-free in vxlan_mdb_flush()
vxlan_mdb_flush() iterates over the MDB entries using hlist_for_each_entry_safe(), which only tolerates the removal of the current entry. Contrary to the comment above the loop, the removal of an entry can trigger the removal of another entry.
Flushing the remotes of a (*, G) entry also removes the (S, G) entries that were created for its source list, once they are left without remotes:
Such an entry can be located after the (*, G) entry in the list, as vxlan_mdb_entry_get() returns an existing entry without moving it to the head of the list.
Leer descripción completaMostrar menos
This order is obtained by adding the (S, G) entry before the (*, G) entry, the latter with NLM_F_REPLACE, as the addition of the source otherwise fails with -EEXIST. The (S, G) entry is then the entry saved by hlist_for_each_entry_safe() and it is freed while the (*, G) entry is processed. The next iteration calls hlist_del() on it again, writing LIST_POISON1 to LIST_POISON2 [1].
Besides device deletion, the flush is also reachable from RTM_DELMDB with NLM_F_BULK.
Fix by re-reading the next entry after the remotes were flushed. The current entry cannot be removed by this flush, as source lists can only be configured on (*, G) entries and the removed entries are (S, G) entries. It is therefore still linked and its next pointer reflects the removals.
Detalles técnicos trazas, registros y código del informe original
vxlan_mdb_remotes_flush()
-> vxlan_mdb_remote_del()
-> vxlan_mdb_remote_srcs_del()
-> vxlan_mdb_remote_src_del()
-> vxlan_mdb_remote_src_fwd_del()
-> __vxlan_mdb_del()
-> vxlan_mdb_entry_put()
[1]
BUG: KASAN: wild-memory-access in vxlan_mdb_entry_put.part.0+0x328/0x588
Write of size 8 at addr dead000000000122 by task ip/327
CPU: 3 UID: 1000 PID: 327 Comm: ip Not tainted 7.2.0-rc7 #2 PREEMPT
Call trace:
vxlan_mdb_entry_put.part.0+0x328/0x588
vxlan_mdb_flush+0x1d8/0x25c
vxlan_mdb_fini+0x8c/0x100
vxlan_uninit+0x1c/0x7c
unregister_netdevice_many_notify+0x954/0xd4c
rtnl_dellink+0x210/0x530
rtnetlink_rcv_msg+0x434/0x4d0
netlink_rcv_skb+0xc4/0x204
rtnetlink_rcv+0x18/0x24
netlink_unicast+0x4b8/0x548
netlink_sendmsg+0x29c/0x560
____sys_sendmsg+0x390/0x3ec
___sys_sendmsg+0x114/0x188
__sys_sendmsg+0xf0/0x178
__arm64_sys_sendmsg+0x48/0x60
invoke_syscall.constprop.0+0x58/0x180
el0_svc_common.constprop.0+0x74/0x140
do_el0_svc+0x30/0x40
el0_svc+0x38/0x98
el0t_64_sync_handler+0xa0/0xe4
el0t_64_sync+0x198/0x19cCVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 4
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1499.004Application or System Exploitationimpact75 % - Impacto secundario
T1561.002Disk Structure Wipeimpact60 %
Vulnerabilidad de use-after-free en kernel de Linux con privilegios locales (PR:L) que permite crash/DoS. El vector AV:L/PR:L/AC:L y la traza KASAN indican explotación local para escalada. Impacto primario es negación de servicio (crash del kernel).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/3e6b705bc162fc7257645725a7d2cf6c71250318
- https://git.kernel.org/stable/c/bc2dc66a6693a78f8c1e6ca2dbebd50f16e2c366
- https://git.kernel.org/stable/c/c7dc26d06f90ca11bbd6114f6a62a67d038816c7
- https://git.kernel.org/stable/c/f26400b325bdc2868e40612c4804c82cf8ba6275
- https://git.kernel.org/stable/c/f8a9b988e7a7bc674e74e8c901794d792c35689e
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93250",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "f8a9b988e7a7bc674e74e8c901794d792c35689e",
"versionType": "git"
},
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "c7dc26d06f90ca11bbd6114f6a62a67d038816c7",
"versionType": "git"
},
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "3e6b705bc162fc7257645725a7d2cf6c71250318",
"versionType": "git"
},
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "f26400b325bdc2868e40612c4804c82cf8ba6275",
"versionType": "git"
},
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "bc2dc66a6693a78f8c1e6ca2dbebd50f16e2c366",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/vxlan/vxlan_mdb.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.4",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/vxlan/vxlan_mdb.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T16:17:21.187",
"references": [
{
"url": "https://git.kernel.org/stable/c/3e6b705bc162fc7257645725a7d2cf6c71250318",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bc2dc66a6693a78f8c1e6ca2dbebd50f16e2c366",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c7dc26d06f90ca11bbd6114f6a62a67d038816c7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f26400b325bdc2868e40612c4804c82cf8ba6275",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f8a9b988e7a7bc674e74e8c901794d792c35689e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: mdb: Fix use-after-free in vxlan_mdb_flush()\n\nvxlan_mdb_flush() iterates over the MDB entries using\nhlist_for_each_entry_safe(), which only tolerates the removal of the\ncurrent entry. Contrary to the comment above the loop, the removal of an\nentry can trigger the removal of another entry.\n\nFlushing the remotes of a (*, G) entry also removes the (S, G) entries\nthat were created for its source list, once they are left without\nremotes:\n\nvxlan_mdb_remotes_flush()\n-> vxlan_mdb_remote_del()\n -> vxlan_mdb_remote_srcs_del()\n -> vxlan_mdb_remote_src_del()\n -> vxlan_mdb_remote_src_fwd_del()\n -> __vxlan_mdb_del()\n -> vxlan_mdb_entry_put()\n\nSuch an entry can be located after the (*, G) entry in the list, as\nvxlan_mdb_entry_get() returns an existing entry without moving it to the\nhead of the list. This order is obtained by adding the (S, G) entry\nbefore the (*, G) entry, the latter with NLM_F_REPLACE, as the addition\nof the source otherwise fails with -EEXIST. The (S, G) entry is then the\nentry saved by hlist_for_each_entry_safe() and it is freed while the\n(*, G) entry is processed. The next iteration calls hlist_del() on it\nagain, writing LIST_POISON1 to LIST_POISON2 [1].\n\nBesides device deletion, the flush is also reachable from RTM_DELMDB\nwith NLM_F_BULK.\n\nFix by re-reading the next entry after the remotes were flushed. The\ncurrent entry cannot be removed by this flush, as source lists can only\nbe configured on (*, G) entries and the removed entries are (S, G)\nentries. It is therefore still linked and its next pointer reflects the\nremovals.\n\n[1]\nBUG: KASAN: wild-memory-access in vxlan_mdb_entry_put.part.0+0x328/0x588\nWrite of size 8 at addr dead000000000122 by task ip/327\n\nCPU: 3 UID: 1000 PID: 327 Comm: ip Not tainted 7.2.0-rc7 #2 PREEMPT\nCall trace:\n vxlan_mdb_entry_put.part.0+0x328/0x588\n vxlan_mdb_flush+0x1d8/0x25c\n vxlan_mdb_fini+0x8c/0x100\n vxlan_uninit+0x1c/0x7c\n unregister_netdevice_many_notify+0x954/0xd4c\n rtnl_dellink+0x210/0x530\n rtnetlink_rcv_msg+0x434/0x4d0\n netlink_rcv_skb+0xc4/0x204\n rtnetlink_rcv+0x18/0x24\n netlink_unicast+0x4b8/0x548\n netlink_sendmsg+0x29c/0x560\n ____sys_sendmsg+0x390/0x3ec\n ___sys_sendmsg+0x114/0x188\n __sys_sendmsg+0xf0/0x178\n __arm64_sys_sendmsg+0x48/0x60\n invoke_syscall.constprop.0+0x58/0x180\n el0_svc_common.constprop.0+0x74/0x140\n do_el0_svc+0x30/0x40\n el0_svc+0x38/0x98\n el0t_64_sync_handler+0xa0/0xe4\n el0t_64_sync+0x198/0x19c"
}
],
"lastModified": "2026-09-25T05:17:00.980",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}