Linux Kernel Vulnerability in VXLAN Affecting Multiple Versions
CVE-2026-80681

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-80681?

A vulnerability exists in the Linux kernel's VXLAN implementation, where an eth header pointer is cached before a routing decision is made. If the routing logic requires reallocating the socket buffer memory, this can lead to the cached pointer referencing freed memory. Consequently, when the pointer is later dereferenced, it risks accessing invalid memory, resulting in a use-after-free condition. This flaw has been addressed by ensuring the eth header is re-fetched after the routing process, thereby preventing potential exploitation.

Affected Version(s)

Linux ae8840825605f36f98f247323edc150e761cb64e < 6375093eb45cd7d89f1945f939eeae3b29d79f56

Linux ae8840825605f36f98f247323edc150e761cb64e < 1b7f7b653e3557690047c62f03b80a24ea5a58a5

Linux ae8840825605f36f98f247323edc150e761cb64e

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.