VXLAN Datagram Encryption Vulnerability in Moby Project
CVE-2026-92542

6.9MEDIUM

What is CVE-2026-92542?

The Moby Project contains a vulnerability where firewall rules for VXLAN datagram encryption in Linux Swarm nodes do not adequately discriminate between legitimate and forged datagrams. Specifically, any UDP packet that fits the criteria of being sent from the host network namespace, directed to the Swarm data-path port, and beginning with a VXLAN header related to an encrypted overlay can be incorrectly encrypted. This issue opens a potential security gap that attackers could exploit by sending crafted packets to gain unauthorized access or disrupt service integrity.

Affected Version(s)

Docker Engine Linux 0 < 25.0.19

Docker Engine Linux 26.0.0 < 29.8.2

Docker Engine overlay network driver Linux 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.