KernelScan.io

CRITICAL Introduced in 3.8

vxlan HeaderPull OOB

CVE-2026-74474

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI4.7MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() for transmit path header pulls In vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was being called to verify the availability of network layer headers (ARP, IPv6/ND, IP/IPv6 MDB keys). However, during transmit skb->data points to the MAC header, so skb_network_offset(skb) is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb->data rather than skb_network_offset(skb) + len, which can leave part of the network header in non-linear frags. Replace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly account for the MAC header offset.

02

Engine v0.6.0

Risk summary

Devices using VXLAN tunneling with DOVE extensions, IPv6 proxy, or MDB support are affected. A local attacker who can send crafted non-linear packets through a configured VXLAN device can trigger an out-of-bounds read in the kernel, potentially causing a kernel panic or incorrect packet handling. The vulnerability is most relevant in multi-tenant and container environments where VXLAN is used for network virtualization.

Affecteddrivers/net/vxlan (vxlan)

Vulnerability analysis

The VXLAN driver's transmit path uses an incorrect function to verify that network-layer headers are available in the packet's linear data area. Because the check does not account for the Ethernet header offset, it can pass even when the network header bytes are actually stored in non-linear fragments. The code then reads the header via direct pointer dereference, accessing memory beyond the linear buffer — an out-of-bounds read. The fix replaces the incorrect calls with the proper variant that accounts for the MAC header offset, ensuring the network header is fully linearized before access. The vulnerable code path is reached when packets are transmitted through a VXLAN device, which requires a VXLAN interface to be configured but can then be triggered by any local process or tenant sending traffic through the device, including container workloads on VXLAN-backed bridges.

03

BranchIntroducedFixed inPatch commit
6.13.86.1.188371425d4be77
6.63.86.6.153bb01c51950c3
6.123.86.12.1056146901881f0
6.183.86.18.4494dee751aad6
7.13.87.1.87076a34b6e33
mainline3.87.2b9553558b48d