VXLAN Driver Vulnerability in Linux Kernel Leading to Potential List Corruption
CVE-2026-98023
What is CVE-2026-98023?
A vulnerability exists in the VXLAN driver of the Linux kernel that allows for the configuration of dynamic FDB (Forwarding Database) entries pointing to FDB nexthops. This can lead to list corruption due to race conditions when multiple VXLAN devices share the same FDB nexthop and attempt to modify the shared list simultaneously. With this vulnerability, it is possible for data operations to conflict, resulting in invalid memory access and potential system instability. The fix involves rejecting dynamic FDB entries that reference nexthop IDs during creation and updates. Proper safeguards should be maintained by ensuring that per-nexthop FDB lists are only modified under secure locking mechanisms.
Affected Version(s)
Linux 1274e1cc42264d4e629841e4f182795cb0becfd2 < 00c7f4b8144e535ffb931ad45942a1bd1315b882
Linux 1274e1cc42264d4e629841e4f182795cb0becfd2 < 55a33882808f1402052d53a08ead59aff8af18a1
Linux 1274e1cc42264d4e629841e4f182795cb0becfd2