Vulnerability in the Linux Kernel's VXLAN Component Affects Data Handling
CVE-2026-80838
What is CVE-2026-80838?
A vulnerability exists in the Linux kernel's VXLAN component, where a bulk flush operation can inadvertently unlink the last remote entry in the Forwarding Database (FDB). This breach in protocol occurs when a filtered flush attempts to clear entries, leading to potential manipulation of data and invalid memory access. Specifically, an RCU reader may reference an empty list head after the last remote is unlinked, enabling a scenario where the receive learning path can mistakenly read from and write to incorrect memory locations. To mitigate this issue, the proper functioning of the FDB must be ensured, so that the last remote remains linked during operations, ensuring data integrity and preventing unauthorized access.
Affected Version(s)
Linux c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f < 2a7c2f00843225d5f037676bca649321f3d024c7
Linux c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f
Linux c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f < 8ba68fd6cdd1e3c92b92f25c7e48bf7bd51a183c