VXLAN Driver Vulnerability in Linux Kernel Leading to Potential List Corruption
CVE-2026-98023

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98023?

A vulnerability exists in the VXLAN driver of the Linux kernel that allows for the configuration of dynamic FDB (Forwarding Database) entries pointing to FDB nexthops. This can lead to list corruption due to race conditions when multiple VXLAN devices share the same FDB nexthop and attempt to modify the shared list simultaneously. With this vulnerability, it is possible for data operations to conflict, resulting in invalid memory access and potential system instability. The fix involves rejecting dynamic FDB entries that reference nexthop IDs during creation and updates. Proper safeguards should be maintained by ensuring that per-nexthop FDB lists are only modified under secure locking mechanisms.

Affected Version(s)

Linux 1274e1cc42264d4e629841e4f182795cb0becfd2 < 00c7f4b8144e535ffb931ad45942a1bd1315b882

Linux 1274e1cc42264d4e629841e4f182795cb0becfd2 < 55a33882808f1402052d53a08ead59aff8af18a1

Linux 1274e1cc42264d4e629841e4f182795cb0becfd2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.