CVE-2026-80681Critical Use-After-Free vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after route_shortcircuit() Before route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb). Inside route_shortcircuit(), pskb_may_pull() can be called, which may reallocate skb->head. In this case, returning to vxlan_xmit() leaves the cached eth pointer pointing to freed memory, leading to a use-after-free when dereferencing eth->h_dest. Fix this by updating eth = eth_hdr(skb) after calling route_shortcircuit().
View on NVDAnalysis
A critical use-after-free vulnerability has been identified in the Linux kernel's VXLAN implementation. This flaw can lead to memory corruption or potential remote code execution in environments using VXLAN overlay networks, which are common in Docker, Kubernetes, and cloud infrastructure.
Relevant roles
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HEPSS
Technical description
In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after route_shortcircuit() Before route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb). Inside route_shortcircuit(), pskb_may_pull() can be called, which may reallocate skb->head. In this case, returning to vxlan_xmit() leaves the cached eth pointer pointing to freed memory, leading to a use-after-free when dereferencing eth->h_dest. Fix this by updating eth = eth_hdr(skb) after calling route_shortcircuit().
References
- https://git.kernel.org/stable/c/1235e017aa11cf01e91b613c4c5ed6aa28934fff
- https://git.kernel.org/stable/c/1395a676ec15a0a02a2a6d86602324f2d5fd41d5
- https://git.kernel.org/stable/c/1511631b7cfc4152b10a0a9d04c7a0bf2ddf4585
- https://git.kernel.org/stable/c/1b7f7b653e3557690047c62f03b80a24ea5a58a5
- https://git.kernel.org/stable/c/2355c8c26d2aa1b4385b369e67202e47d460d555
- https://git.kernel.org/stable/c/6375093eb45cd7d89f1945f939eeae3b29d79f56
- https://git.kernel.org/stable/c/bf045341dfb3e767f0ff94cf240ce3c371973bd4
- https://git.kernel.org/stable/c/c9dceac9e1c7c772c43c732fc0d325e72835801a