KernelScan.io

CRITICAL Introduced in 4.7

vxlan GroReceive Race

CVE-2026-74406

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI4.7MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). udp_tunnel_sock_release() could set sk->sk_user_data to NULL while vxlan_gro_prepare_receive() is running. Let's check if rcu_dereference_sk_user_data() is NULL after skb_gro_remcsum_init().

02

Engine v0.6.0

Risk summary

A race condition in the VXLAN GRO receive path can cause a kernel NULL pointer dereference when a socket is torn down concurrently with packet processing. An attacker with local access who can create and destroy VXLAN sockets (CAP_NET_ADMIN, obtainable in a user namespace) while injecting packets can crash the kernel. The impact is denial of service; no memory corruption or information disclosure is involved.

Affecteddrivers/net/vxlan/vxlan_core.c (vxlan)

Vulnerability analysis

During VXLAN packet processing, the socket's user-data pointer is read and cached early, but a concurrent socket teardown can clear that pointer before it is used, resulting in a NULL pointer dereference and kernel panic. The fix moves the pointer read to immediately before its use and adds a NULL check so that if teardown has already occurred, the function safely bails out instead of dereferencing the stale value. The vulnerable path is reachable by a local attacker who can both inject VXLAN packets and trigger socket release—both possible with CAP_NET_ADMIN, which an unprivileged user can obtain through a user namespace.

03

BranchIntroducedFixed inPatch commit
6.124.76.12.9708f40c0d23c6
mainline4.77.2-rc130a45c0bffdd
6.184.76.18.404a8cde6f7281
6.14.76.1.1789c58c729d32e
6.64.76.6.145f79c80f173fd
7.14.77.1.5ef44dac2a37f