Use-After-Free Vulnerability in Linux Kernel VXLAN Component
CVE-2026-93250
What is CVE-2026-93250?
A use-after-free vulnerability exists in the Linux kernel's VXLAN component during the execution of the vxlan_mdb_flush() function. This flaw arises from improper iteration over the Multi-Destination Broadcast (MDB) entries, which allows the simultaneous deletion of multiple entries, leading to potential wild memory access issues. Specifically, when flushing remote entries of a multicast group, the function inadvertently frees associated source entries that were not designed to be removed during this process. As a result, subsequent calls to previous entries could lead to memory corruption, causing unexpected behavior in the kernel. It is crucial for users and administrators to apply the latest updates to mitigate any potential security threats associated with this vulnerability.
Affected Version(s)
Linux a3a48de5eade770e911d35291217bdd69ce04ef1
Linux a3a48de5eade770e911d35291217bdd69ce04ef1
Linux a3a48de5eade770e911d35291217bdd69ce04ef1 < 3e6b705bc162fc7257645725a7d2cf6c71250318