CVE-2026-98023
In the Linux kernel, the following vulnerability has been resolved:
vxlan: reject dynamic fdb entries that reference a nexthop id
The commit cited in the Fixes tag allowed VXLAN FDB entries to point to FDB nexthops so that overlay traffic could be load balanced across multiple VTEPs. Such entries can only be configured from user space, cannot be learned and cannot roam. They only make sense with a user space control plane such as E-VPN where data plane learning is disabled.
Despite that, the VXLAN driver does not currently prevent such entries from being configured with the "dynamic" flag.
Leer descripción completaMostrar menos
The per-nexthop FDB list is only protected by the per-device hash lock, which is not sufficient when two VXLAN devices point to the same FDB nexthop and therefore share the list. Aging runs in softirq context without RTNL, so an entry deleted by one device can race with an addition or deletion from the other, leading to list corruption:
Fix this by rejecting the bogus configuration of dynamic FDB entries that point to FDB nexthops, both when created and when an existing entry is updated. As such, the per-nexthop FDB list is only ever mutated under the RTNL lock. Add test cases to make sure that this does not regress in the future.
Detalles técnicos trazas, registros y código del informe original
list_del corruption. next->prev should be ffff8881069d9548, but was dead000000000122. (next=ffff8881069d9448) WARNING: CPU: 0 PID: 90 at lib/list_debug.c:65 __list_del_entry_valid_or_report+0x1aa/0x210 ... vxlan_fdb_destroy+0x5b8/0xad0 vxlan_cleanup+0x328/0x450 call_timer_fn+0x2a/0x1c0 run_timer_softirq+0x18c/0x210 BUG: KASAN: slab-use-after-free in vxlan_fdb_destroy
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.13%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1499.004Application or System Exploitationimpact75 % - Impacto secundario
T1565.001Stored Data Manipulationimpact60 %
Escalada de privilegios local sin requerir interacción (PR:L, UI:N). La corrupción de lista y race condition en softirq permite DoS y potencial corrupción de datos de red.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/00c7f4b8144e535ffb931ad45942a1bd1315b882
- https://git.kernel.org/stable/c/28f86eec851b7406a4bc6143f82aeba2882d9842
- https://git.kernel.org/stable/c/3fa64d86fc64eda104e3e97721a12a42a2fd2073
- https://git.kernel.org/stable/c/53359916ceb649b7e6947c8c2f669368a41c1354
- https://git.kernel.org/stable/c/55a33882808f1402052d53a08ead59aff8af18a1
- https://git.kernel.org/stable/c/98fc57d167446b95b4e719815fe79edef93f8e7a
- https://git.kernel.org/stable/c/b2a8e165ddb6cd72176890b2954c52b0f6dbce1a
- https://git.kernel.org/stable/c/c8f29af91e0830fdabc9aa1eb1a0f898ce1bc603
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98023",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
"lessThan": "00c7f4b8144e535ffb931ad45942a1bd1315b882",
"versionType": "git"
},
{
"status": "affected",
"version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
"lessThan": "55a33882808f1402052d53a08ead59aff8af18a1",
"versionType": "git"
},
{
"status": "affected",
"version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
"lessThan": "c8f29af91e0830fdabc9aa1eb1a0f898ce1bc603",
"versionType": "git"
},
{
"status": "affected",
"version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
"lessThan": "b2a8e165ddb6cd72176890b2954c52b0f6dbce1a",
"versionType": "git"
},
{
"status": "affected",
"version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
"lessThan": "28f86eec851b7406a4bc6143f82aeba2882d9842",
"versionType": "git"
},
{
"status": "affected",
"version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
"lessThan": "53359916ceb649b7e6947c8c2f669368a41c1354",
"versionType": "git"
},
{
"status": "affected",
"version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
"lessThan": "3fa64d86fc64eda104e3e97721a12a42a2fd2073",
"versionType": "git"
},
{
"status": "affected",
"version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
"lessThan": "98fc57d167446b95b4e719815fe79edef93f8e7a",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/vxlan/vxlan_core.c",
"tools/testing/selftests/net/fib_nexthops.sh"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.8",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/vxlan/vxlan_core.c",
"tools/testing/selftests/net/fib_nexthops.sh"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:30.873",
"references": [
{
"url": "https://git.kernel.org/stable/c/00c7f4b8144e535ffb931ad45942a1bd1315b882",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/28f86eec851b7406a4bc6143f82aeba2882d9842",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3fa64d86fc64eda104e3e97721a12a42a2fd2073",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/53359916ceb649b7e6947c8c2f669368a41c1354",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/55a33882808f1402052d53a08ead59aff8af18a1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/98fc57d167446b95b4e719815fe79edef93f8e7a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b2a8e165ddb6cd72176890b2954c52b0f6dbce1a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c8f29af91e0830fdabc9aa1eb1a0f898ce1bc603",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: reject dynamic fdb entries that reference a nexthop id\n\nThe commit cited in the Fixes tag allowed VXLAN FDB entries to point to\nFDB nexthops so that overlay traffic could be load balanced across\nmultiple VTEPs. Such entries can only be configured from user space,\ncannot be learned and cannot roam. They only make sense with a user space\ncontrol plane such as E-VPN where data plane learning is disabled.\n\nDespite that, the VXLAN driver does not currently prevent such entries\nfrom being configured with the \"dynamic\" flag. The per-nexthop FDB list\nis only protected by the per-device hash lock, which is not sufficient\nwhen two VXLAN devices point to the same FDB nexthop and therefore share\nthe list. Aging runs in softirq context without RTNL, so an entry deleted\nby one device can race with an addition or deletion from the other,\nleading to list corruption:\n\n list_del corruption. next->prev should be ffff8881069d9548, but was\n dead000000000122. (next=ffff8881069d9448)\n WARNING: CPU: 0 PID: 90 at lib/list_debug.c:65\n __list_del_entry_valid_or_report+0x1aa/0x210\n ...\n vxlan_fdb_destroy+0x5b8/0xad0\n vxlan_cleanup+0x328/0x450\n call_timer_fn+0x2a/0x1c0\n run_timer_softirq+0x18c/0x210\n BUG: KASAN: slab-use-after-free in vxlan_fdb_destroy\n\nFix this by rejecting the bogus configuration of dynamic FDB entries that\npoint to FDB nexthops, both when created and when an existing entry is\nupdated. As such, the per-nexthop FDB list is only ever mutated under the\nRTNL lock. Add test cases to make sure that this does not regress in the\nfuture."
}
],
"lastModified": "2026-10-03T11:18:25.280",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}