CRITICAL Introduced in 3.8
vxlan RouteShortcircuit Race
CVE-2026-74475
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
KernelScan AI3.7LOW
01Description
In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() in route_shortcircuit() The neighbour hardware address n->ha can be updated asynchronously by the neighbour subsystem, protected by n->ha_lock seqlock. Reading n->ha without holding the seqlock loop can lead to torn reads or reading a partially updated MAC address. Use neigh_ha_snapshot() in route_shortcircuit() to safely copy n->ha under read_seqbegin()/read_seqretry() lock protection before using it. Note that arp_reduce() and neigh_reduce() seem to have the same issue left for future patches.
02KernelScan AI Analysis
Risk summary
A race condition in the VXLAN driver's DOVE route short-circuiting feature allows a network attacker to trigger torn reads of a neighbour MAC address. The impact is limited to packet misdelivery within the VXLAN overlay — no memory corruption, information disclosure, or privilege escalation. Exploitation requires precise timing between packet transmission and asynchronous neighbour updates.
Vulnerability analysis
When the VXLAN DOVE route short-circuiting feature forwards a packet, it reads the destination neighbour's hardware address without the seqlock protection that the neighbour subsystem requires. Because that address can be updated concurrently by ARP or neighbour-discovery processing, the reader can observe a partially written MAC address — a torn read. The fix replaces the unprotected direct read with a helper that atomically snapshots the hardware address under the seqlock before using it. The vulnerable path is reached when packets are transmitted through a VXLAN device configured with DOVE extensions; an attacker on the network can trigger the race by sending traffic that causes concurrent neighbour-entry updates while the local system is forwarding packets through the overlay.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 3.8 | 5.10.265 | 32a9590a8d30 |
| 6.18 | 3.8 | 6.18.44 | ff89415d34c3 |
| 7.1 | 3.8 | 7.1.8 | 05f2987f73da |
| 6.6 | 3.8 | 6.6.151 | d08e8ac13f2e |
| 5.15 | 3.8 | 5.15.216 | d0993fc053f2 |
| 6.12 | 3.8 | 6.12.103 | ec341bb76d77 |
| 6.1 | 3.8 | 6.1.183 | 87210054bad8 |
| mainline | 3.8 | 7.2 | 8eca411347e1 |