CRITICAL Introduced in 4.7
vxlan GroReceive Race
CVE-2026-74406
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI4.7MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). udp_tunnel_sock_release() could set sk->sk_user_data to NULL while vxlan_gro_prepare_receive() is running. Let's check if rcu_dereference_sk_user_data() is NULL after skb_gro_remcsum_init().
02KernelScan AI Analysis
Risk summary
A race condition in the VXLAN GRO receive path can cause a kernel NULL pointer dereference when a socket is torn down concurrently with packet processing. An attacker with local access who can create and destroy VXLAN sockets (CAP_NET_ADMIN, obtainable in a user namespace) while injecting packets can crash the kernel. The impact is denial of service; no memory corruption or information disclosure is involved.
Vulnerability analysis
During VXLAN packet processing, the socket's user-data pointer is read and cached early, but a concurrent socket teardown can clear that pointer before it is used, resulting in a NULL pointer dereference and kernel panic. The fix moves the pointer read to immediately before its use and adds a NULL check so that if teardown has already occurred, the function safely bails out instead of dereferencing the stale value. The vulnerable path is reachable by a local attacker who can both inject VXLAN packets and trigger socket release—both possible with CAP_NET_ADMIN, which an unprivileged user can obtain through a user namespace.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 4.7 | 6.12.97 | 08f40c0d23c6 |
| mainline | 4.7 | 7.2-rc1 | 30a45c0bffdd |
| 6.18 | 4.7 | 6.18.40 | 4a8cde6f7281 |
| 6.1 | 4.7 | 6.1.178 | 9c58c729d32e |
| 6.6 | 4.7 | 6.6.145 | f79c80f173fd |
| 7.1 | 4.7 | 7.1.5 | ef44dac2a37f |