KernelScan.io

CRITICAL Introduced in 3.8

vxlan RouteShortcircuit Race

CVE-2026-74475

CVSS 10.0 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

KernelScan AI3.7LOW

01

In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() in route_shortcircuit() The neighbour hardware address n->ha can be updated asynchronously by the neighbour subsystem, protected by n->ha_lock seqlock. Reading n->ha without holding the seqlock loop can lead to torn reads or reading a partially updated MAC address. Use neigh_ha_snapshot() in route_shortcircuit() to safely copy n->ha under read_seqbegin()/read_seqretry() lock protection before using it. Note that arp_reduce() and neigh_reduce() seem to have the same issue left for future patches.

02

Engine v0.6.0

Risk summary

A race condition in the VXLAN driver's DOVE route short-circuiting feature allows a network attacker to trigger torn reads of a neighbour MAC address. The impact is limited to packet misdelivery within the VXLAN overlay — no memory corruption, information disclosure, or privilege escalation. Exploitation requires precise timing between packet transmission and asynchronous neighbour updates.

Affecteddrivers/net/vxlan/vxlan_core.c (vxlan)

Vulnerability analysis

When the VXLAN DOVE route short-circuiting feature forwards a packet, it reads the destination neighbour's hardware address without the seqlock protection that the neighbour subsystem requires. Because that address can be updated concurrently by ARP or neighbour-discovery processing, the reader can observe a partially written MAC address — a torn read. The fix replaces the unprotected direct read with a helper that atomically snapshots the hardware address under the seqlock before using it. The vulnerable path is reached when packets are transmitted through a VXLAN device configured with DOVE extensions; an attacker on the network can trigger the race by sending traffic that causes concurrent neighbour-entry updates while the local system is forwarding packets through the overlay.

03

BranchIntroducedFixed inPatch commit
5.103.85.10.26532a9590a8d30
6.183.86.18.44ff89415d34c3
7.13.87.1.805f2987f73da
6.63.86.6.151d08e8ac13f2e
5.153.85.15.216d0993fc053f2
6.123.86.12.103ec341bb76d77
6.13.86.1.18387210054bad8
mainline3.87.28eca411347e1