CRITICAL Introduced in 3.8
vxlan HeaderPull OOB
CVE-2026-74474
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI4.7MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() for transmit path header pulls In vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was being called to verify the availability of network layer headers (ARP, IPv6/ND, IP/IPv6 MDB keys). However, during transmit skb->data points to the MAC header, so skb_network_offset(skb) is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb->data rather than skb_network_offset(skb) + len, which can leave part of the network header in non-linear frags. Replace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly account for the MAC header offset.
02KernelScan AI Analysis
Risk summary
Devices using VXLAN tunneling with DOVE extensions, IPv6 proxy, or MDB support are affected. A local attacker who can send crafted non-linear packets through a configured VXLAN device can trigger an out-of-bounds read in the kernel, potentially causing a kernel panic or incorrect packet handling. The vulnerability is most relevant in multi-tenant and container environments where VXLAN is used for network virtualization.
Vulnerability analysis
The VXLAN driver's transmit path uses an incorrect function to verify that network-layer headers are available in the packet's linear data area. Because the check does not account for the Ethernet header offset, it can pass even when the network header bytes are actually stored in non-linear fragments. The code then reads the header via direct pointer dereference, accessing memory beyond the linear buffer — an out-of-bounds read. The fix replaces the incorrect calls with the proper variant that accounts for the MAC header offset, ensuring the network header is fully linearized before access. The vulnerable code path is reached when packets are transmitted through a VXLAN device, which requires a VXLAN interface to be configured but can then be triggered by any local process or tenant sending traffic through the device, including container workloads on VXLAN-backed bridges.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.1 | 3.8 | 6.1.188 | 371425d4be77 |
| 6.6 | 3.8 | 6.6.153 | bb01c51950c3 |
| 6.12 | 3.8 | 6.12.105 | 6146901881f0 |
| 6.18 | 3.8 | 6.18.44 | 94dee751aad6 |
| 7.1 | 3.8 | 7.1.8 | 7076a34b6e33 |
| mainline | 3.8 | 7.2 | b9553558b48d |