CVE-2026-98122
In the Linux kernel, the following vulnerability has been resolved:
vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()
vxlan_mdb_is_valid_source(), which validates MDBE_ATTR_SOURCE and every MDBE_ATTR_SRC_LIST member, accepts the all-zeros address.
A source list is only accepted on a (*, G) entry, whose source is the all-zeros address, and for each member of the list an (S, G) entry is derived from it by substituting the source.
Leer descripción completaMostrar menos
Entries are keyed by a plain memcmp() of struct vxlan_mdb_entry_key, so if MDBE_ATTR_SOURCE is present and holds the all-zeros address and the source list holds it as well, the derived (S, G) key is byte-identical to the (*, G) key and resolves to the same entry. Omitting MDBE_ATTR_SOURCE is not equivalent, as the key is then left with a zero address family.
vxlan_mdb_remote_src_del() removes the forwarding entry of a source before freeing the source entry:
With the keys aliased, the first call deletes the remote of the entry that owns 'ent' instead of a separate (S, G) entry, and frees 'ent'. The second call then runs on the freed entry, and its hlist_del() reads ->pprev and ->next out of it and writes through them.
Adding the (*, G) entry with NLM_F_REPLACE and no source list marks the all-zeros source for deletion and reaches this from the sweep at the end of vxlan_mdb_remote_srcs_replace().
The MDB operations are netns-scoped, so an unprivileged user can perform them in a new user and network namespace.
Reject the all-zeros address in vxlan_mdb_is_valid_source(), which covers both call sites. A (*, G) entry is expressed by omitting the source, so nothing legitimate is refused.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
Detalles técnicos trazas, registros y código del informe original
vxlan_mdb_remote_src_fwd_del(vxlan, group, remote, &ent->addr); vxlan_mdb_remote_src_entry_del(ent); BUG: KASAN: slab-use-after-free in __vxlan_mdb_add+0x1cd/0xd70 Read of size 8 at addr ffff888102852500 by task poc/84 __vxlan_mdb_add+0x1cd/0xd70 vxlan_mdb_add+0xc0/0x140 rtnl_mdb_add+0x157/0x2a0 rtnetlink_rcv_msg+0x207/0x5a0 Allocated by task 84: __kmalloc_cache_noprof+0x153/0x360 vxlan_mdb_remote_srcs_add+0x2eb/0x440 __vxlan_mdb_add+0x803/0xd70 Freed by task 84: kfree+0x14c/0x3b0 vxlan_mdb_remote_del+0x129/0x1a0 __vxlan_mdb_del+0x4f/0xe0 vxlan_mdb_remote_src_fwd_del.isra.0+0x162/0x1b0 __vxlan_mdb_add+0x1c5/0xd70
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.13%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation95 % - Impacto principal
T1499.004Application or System Exploitationimpact85 % - Impacto secundario
T1561.002Disk Structure Wipeimpact60 %
Vulnerabilidad local en kernel Linux (AV:L/PR:L) explotable por usuario sin privilegios en namespace; causa use-after-free que permite DoS y potencial corrupción de memoria del sistema.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/069d5527bb0f229e528fa88c6b72f15060c373f2
- https://git.kernel.org/stable/c/4aa61c88b4e292e10abdfd791334b8272108d68a
- https://git.kernel.org/stable/c/71203a41d6fa2fa0ea2f3a7541987958bd3694fd
- https://git.kernel.org/stable/c/74e2a56c82209b0335b53e25f19f9b0590e2483d
- https://git.kernel.org/stable/c/e12c903fd13c6261b98ca18d8f70ac26e739e2f8
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98122",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "069d5527bb0f229e528fa88c6b72f15060c373f2",
"versionType": "git"
},
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "e12c903fd13c6261b98ca18d8f70ac26e739e2f8",
"versionType": "git"
},
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "74e2a56c82209b0335b53e25f19f9b0590e2483d",
"versionType": "git"
},
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "71203a41d6fa2fa0ea2f3a7541987958bd3694fd",
"versionType": "git"
},
{
"status": "affected",
"version": "a3a48de5eade770e911d35291217bdd69ce04ef1",
"lessThan": "4aa61c88b4e292e10abdfd791334b8272108d68a",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/vxlan/vxlan_mdb.c",
"tools/testing/selftests/net/test_vxlan_mdb.sh"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.4",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/vxlan/vxlan_mdb.c",
"tools/testing/selftests/net/test_vxlan_mdb.sh"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:43.470",
"references": [
{
"url": "https://git.kernel.org/stable/c/069d5527bb0f229e528fa88c6b72f15060c373f2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4aa61c88b4e292e10abdfd791334b8272108d68a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/71203a41d6fa2fa0ea2f3a7541987958bd3694fd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/74e2a56c82209b0335b53e25f19f9b0590e2483d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e12c903fd13c6261b98ca18d8f70ac26e739e2f8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Undergoing Analysis",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()\n\nvxlan_mdb_is_valid_source(), which validates MDBE_ATTR_SOURCE and every\nMDBE_ATTR_SRC_LIST member, accepts the all-zeros address.\n\nA source list is only accepted on a (*, G) entry, whose source is the\nall-zeros address, and for each member of the list an (S, G) entry is\nderived from it by substituting the source. Entries are keyed by a plain\nmemcmp() of struct vxlan_mdb_entry_key, so if MDBE_ATTR_SOURCE is present\nand holds the all-zeros address and the source list holds it as well, the\nderived (S, G) key is byte-identical to the (*, G) key and resolves to the\nsame entry. Omitting MDBE_ATTR_SOURCE is not equivalent, as the key is\nthen left with a zero address family.\n\nvxlan_mdb_remote_src_del() removes the forwarding entry of a source before\nfreeing the source entry:\n\n\tvxlan_mdb_remote_src_fwd_del(vxlan, group, remote, &ent->addr);\n\tvxlan_mdb_remote_src_entry_del(ent);\n\nWith the keys aliased, the first call deletes the remote of the entry that\nowns 'ent' instead of a separate (S, G) entry, and frees 'ent'. The second\ncall then runs on the freed entry, and its hlist_del() reads ->pprev and\n->next out of it and writes through them.\n\nAdding the (*, G) entry with NLM_F_REPLACE and no source list marks the\nall-zeros source for deletion and reaches this from the sweep at the end\nof vxlan_mdb_remote_srcs_replace().\n\n BUG: KASAN: slab-use-after-free in __vxlan_mdb_add+0x1cd/0xd70\n Read of size 8 at addr ffff888102852500 by task poc/84\n __vxlan_mdb_add+0x1cd/0xd70\n vxlan_mdb_add+0xc0/0x140\n rtnl_mdb_add+0x157/0x2a0\n rtnetlink_rcv_msg+0x207/0x5a0\n Allocated by task 84:\n __kmalloc_cache_noprof+0x153/0x360\n vxlan_mdb_remote_srcs_add+0x2eb/0x440\n __vxlan_mdb_add+0x803/0xd70\n Freed by task 84:\n kfree+0x14c/0x3b0\n vxlan_mdb_remote_del+0x129/0x1a0\n __vxlan_mdb_del+0x4f/0xe0\n vxlan_mdb_remote_src_fwd_del.isra.0+0x162/0x1b0\n __vxlan_mdb_add+0x1c5/0xd70\n\nThe MDB operations are netns-scoped, so an unprivileged user can perform\nthem in a new user and network namespace.\n\nReject the all-zeros address in vxlan_mdb_is_valid_source(), which covers\nboth call sites. A (*, G) entry is expressed by omitting the source, so\nnothing legitimate is refused.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"
}
],
"lastModified": "2026-10-03T11:18:33.937",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}