KernelScan.io

CRITICAL Introduced in 3.8

vxlan RouteShortcircuit OOB

CVE-2026-74473

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI5.3MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() in route_shortcircuit() route_shortcircuit() currently calls pskb_may_pull(skb, sizeof(struct iphdr)) (or ipv6hdr), which checks if bytes are available starting from skb->data. However, in vxlan_xmit(), skb->data points to the MAC header, so skb_network_offset(skb) is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, 20) only checks 20 bytes from skb->data (which is 14 bytes MAC header + 6 bytes of IP header), leaving the rest of the IP header potentially un-pulled in non-linear frags. Subsequent dereferences of ip_hdr(skb)->daddr can read beyond the pulled linear buffer length. Fix this by using pskb_network_may_pull(), which adds skb_network_offset(skb) to the length check to ensure the full network header is present in the linear buffer.

02

Engine v0.6.0

Risk summary

A network attacker who can send traffic through a VXLAN device configured with route short-circuiting (DOVE) can trigger an out-of-bounds read of the IP destination address from non-linear socket buffer fragments. The read is bounded in size but can access stale or incorrect memory, leading to potential information disclosure, misrouted packets, or a kernel panic. Systems without VXLAN RSC enabled are not affected.

Affecteddrivers/net/vxlan/vxlan_core.c (vxlan)

Vulnerability analysis

The VXLAN driver's route short-circuit feature validates that enough bytes are available in a packet's linear buffer before reading the IP destination address, but the check starts from the MAC header position rather than the network header position. Because of this offset, only a partial IP header is guaranteed to be linear; when the remainder sits in non-linear fragments, reading the destination address field accesses memory beyond the validated region. The fix switches to a validation helper that accounts for the network header offset, ensuring the full IP or IPv6 header is present in the linear buffer before any field is dereferenced. The vulnerable path is reached when a VXLAN device is configured with route short-circuiting enabled and processes transit packets; an attacker on any network that can route traffic through such a device can trigger the condition by sending packets whose internal layout becomes non-linear during kernel processing.

03

BranchIntroducedFixed inPatch commit
5.153.85.15.2166bd0a3a1b574
6.13.86.1.183214ba43faf10
6.63.86.6.15142887be7c4cf
6.123.86.12.103aa0d31376d57
7.13.87.1.84f3f96e771a2
mainline3.87.226bb2dd0a883
5.103.85.10.265c419af4924c1
6.183.86.18.44ee799977d794