« Volver al listado

CVE-2026-98023

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

vxlan: reject dynamic fdb entries that reference a nexthop id

The commit cited in the Fixes tag allowed VXLAN FDB entries to point to FDB nexthops so that overlay traffic could be load balanced across multiple VTEPs. Such entries can only be configured from user space, cannot be learned and cannot roam. They only make sense with a user space control plane such as E-VPN where data plane learning is disabled.

Despite that, the VXLAN driver does not currently prevent such entries from being configured with the "dynamic" flag.

Leer descripción completaMostrar menos

The per-nexthop FDB list is only protected by the per-device hash lock, which is not sufficient when two VXLAN devices point to the same FDB nexthop and therefore share the list. Aging runs in softirq context without RTNL, so an entry deleted by one device can race with an addition or deletion from the other, leading to list corruption:

Fix this by rejecting the bogus configuration of dynamic FDB entries that point to FDB nexthops, both when created and when an existing entry is updated. As such, the per-nexthop FDB list is only ever mutated under the RTNL lock. Add test cases to make sure that this does not regress in the future.

Detalles técnicos trazas, registros y código del informe original
  list_del corruption. next->prev should be ffff8881069d9548, but was
  dead000000000122. (next=ffff8881069d9448)
  WARNING: CPU: 0 PID: 90 at lib/list_debug.c:65
  __list_del_entry_valid_or_report+0x1aa/0x210
  ...
   vxlan_fdb_destroy+0x5b8/0xad0
   vxlan_cleanup+0x328/0x450
   call_timer_fn+0x2a/0x1c0
   run_timer_softirq+0x18c/0x210
  BUG: KASAN: slab-use-after-free in vxlan_fdb_destroy

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Escalada de privilegios local sin requerir interacción (PR:L, UI:N). La corrupción de lista y race condition en softirq permite DoS y potencial corrupción de datos de red.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98023",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
              "lessThan": "00c7f4b8144e535ffb931ad45942a1bd1315b882",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
              "lessThan": "55a33882808f1402052d53a08ead59aff8af18a1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
              "lessThan": "c8f29af91e0830fdabc9aa1eb1a0f898ce1bc603",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
              "lessThan": "b2a8e165ddb6cd72176890b2954c52b0f6dbce1a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
              "lessThan": "28f86eec851b7406a4bc6143f82aeba2882d9842",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
              "lessThan": "53359916ceb649b7e6947c8c2f669368a41c1354",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
              "lessThan": "3fa64d86fc64eda104e3e97721a12a42a2fd2073",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1274e1cc42264d4e629841e4f182795cb0becfd2",
              "lessThan": "98fc57d167446b95b4e719815fe79edef93f8e7a",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/vxlan/vxlan_core.c",
            "tools/testing/selftests/net/fib_nexthops.sh"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/vxlan/vxlan_core.c",
            "tools/testing/selftests/net/fib_nexthops.sh"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:30.873",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/00c7f4b8144e535ffb931ad45942a1bd1315b882",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/28f86eec851b7406a4bc6143f82aeba2882d9842",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3fa64d86fc64eda104e3e97721a12a42a2fd2073",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/53359916ceb649b7e6947c8c2f669368a41c1354",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/55a33882808f1402052d53a08ead59aff8af18a1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/98fc57d167446b95b4e719815fe79edef93f8e7a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b2a8e165ddb6cd72176890b2954c52b0f6dbce1a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c8f29af91e0830fdabc9aa1eb1a0f898ce1bc603",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: reject dynamic fdb entries that reference a nexthop id\n\nThe commit cited in the Fixes tag allowed VXLAN FDB entries to point to\nFDB nexthops so that overlay traffic could be load balanced across\nmultiple VTEPs. Such entries can only be configured from user space,\ncannot be learned and cannot roam. They only make sense with a user space\ncontrol plane such as E-VPN where data plane learning is disabled.\n\nDespite that, the VXLAN driver does not currently prevent such entries\nfrom being configured with the \"dynamic\" flag. The per-nexthop FDB list\nis only protected by the per-device hash lock, which is not sufficient\nwhen two VXLAN devices point to the same FDB nexthop and therefore share\nthe list. Aging runs in softirq context without RTNL, so an entry deleted\nby one device can race with an addition or deletion from the other,\nleading to list corruption:\n\n  list_del corruption. next->prev should be ffff8881069d9548, but was\n  dead000000000122. (next=ffff8881069d9448)\n  WARNING: CPU: 0 PID: 90 at lib/list_debug.c:65\n  __list_del_entry_valid_or_report+0x1aa/0x210\n  ...\n   vxlan_fdb_destroy+0x5b8/0xad0\n   vxlan_cleanup+0x328/0x450\n   call_timer_fn+0x2a/0x1c0\n   run_timer_softirq+0x18c/0x210\n  BUG: KASAN: slab-use-after-free in vxlan_fdb_destroy\n\nFix this by rejecting the bogus configuration of dynamic FDB entries that\npoint to FDB nexthops, both when created and when an existing entry is\nupdated. As such, the per-nexthop FDB list is only ever mutated under the\nRTNL lock. Add test cases to make sure that this does not regress in the\nfuture."
    }
  ],
  "lastModified": "2026-10-03T11:18:25.280",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}