← All Advisories

CVE-2026-98122

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-98122

Key Details

CVECVE-2026-98122
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()

vxlan_mdb_is_valid_source(), which validates MDBE_ATTR_SOURCE and every

MDBE_ATTR_SRC_LIST member, accepts the all-zeros address.

A source list is only accepted on a (*, G) entry, whose source is the

all-zeros address, and for each member of the list an (S, G) entry is

derived from it by substituting the source. Entries are keyed by a plain

memcmp() of struct vxlan_mdb_entry_key, so if MDBE_ATTR_SOURCE is present

and holds the all-zeros address and the source list holds it as well, the

derived (S, G) key is byte-identical to the (*, G) key and resolves to the

same entry. Omitting MDBE_ATTR_SOURCE is not equivalent, as the key is

then left with a zero address family.

vxlan_mdb_remote_src_del() removes the forwarding entry of a source before

freeing the source entry:

vxlan_mdb_remote_src_fwd_del(vxlan, group, remote, &ent->addr);

vxlan_mdb_remote_src_entry_del(ent);

With the keys aliased, the first call deletes the remote of the entry that

owns 'ent' instead of a separate (S, G) entry, and frees 'ent'. The second

call then runs on the freed entry, and its hlist_del() reads ->pprev and

->next out of it and writes through them.

Adding the (*, G) entry with NLM_F_REPLACE and no source list marks the

all-zeros source for deletion and reaches this from the sweep at the end

of vxlan_mdb_remote_srcs_replace().

BUG: KASAN: slab-use-after-free in __vxlan_mdb_add+0x1cd/0xd70

Read of size 8 at addr ffff888102852500 by task poc/84

__vxlan_mdb_add+0x1cd/0xd70

vxlan_mdb_add+0xc0/0x140

rtnl_mdb_add+0x157/0x2a0

rtnetlink_rcv_msg+0x207/0x5a0

Allocated by task 84:

__kmalloc_cache_noprof+0x153/0x360

vxlan_mdb_remote_srcs_add+0x2eb/0x440

__vxlan_mdb_add+0x803/0xd70

Freed by task 84:

kfree+0x14c/0x3b0

vxlan_mdb_remote_del+0x129/0x1a0

__vxlan_mdb_del+0x4f/0xe0

vxlan_mdb_remote_src_fwd_del.isra.0+0x162/0x1b0

__vxlan_mdb_add+0x1c5/0xd70

The MDB operations are netns-scoped, so an unprivileged user can perform

them in a new user and network namespace.

Reject the all-zeros address in vxlan_mdb_is_valid_source(), which covers

both call sites. A (*, G) entry is expressed by omitting the source, so

nothing legitimate is refused.

Discovered by XBOW, triaged by Baul Lee <[email protected]> (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98122
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98122