CVE-2026-80838

Unknown

Last modified

CVE-2026-80838 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: vxlan: keep the last remote linked during FDB flush A non-nexthop FDB entry is expected to have at least one remote while it remains reachable through the FDB hash table. A filtered bulk flush violates this invariant when every remote matches: It unlinks the last remote in vxlan_fdb_dst_destroy() and only afterwards tells vxlan_flush() to destroy the parent FDB entry. An RCU reader can find the parent during this interval. first_remote_rcu() then applies list_entry_rcu() to the empty list head, producing an invalid remote pointer that the receive learning path can read from and write to. When a matching remote is the sole remaining remote, leave it linked and ask the caller to destroy the entire FDB entry.

Description

In the Linux kernel, the following vulnerability has been resolved: vxlan: keep the last remote linked during FDB flush A non-nexthop FDB entry is expected to have at least one remote while it remains reachable through the FDB hash table. A filtered bulk flush violates this invariant when every remote matches: It unlinks the last remote in vxlan_fdb_dst_destroy() and only afterwards tells vxlan_flush() to destroy the parent FDB entry. An RCU reader can find the parent during this interval. first_remote_rcu() then applies list_entry_rcu() to the empty list head, producing an invalid remote pointer that the receive learning path can read from and write to. When a matching remote is the sole remaining remote, leave it linked and ask the caller to destroy the entire FDB entry. vxlan_fdb_destroy() keeps the remote attached while sending the deletion notification and removing the parent from the lookup structures.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f, < 2a7c2f00843225d5f037676bca649321f3d024c7; >= c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f, < a8820c8a7718327e96849782033e7c85a0f6bcfe; >= c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f, < 8ba68fd6cdd1e3c92b92f25c7e48bf7bd51a183c; >= c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f, < 4bbc76ee1b21d3bd045d6d819b2bacd30a6372ab; >= c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f, < d5d4a7b538b52db63927773a8905fcd9f78a42e2
LinuxLinux6.7

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-80838?
In the Linux kernel, the following vulnerability has been resolved: vxlan: keep the last remote linked during FDB flush A non-nexthop FDB entry is expected to have at least one remote while it remains reachable through the FDB hash table. A filtered bulk flush violates this invariant when every remote matches: It unlinks the last remote in vxlan_fdb_dst_destroy() and only afterwards tells vxlan_flush() to destroy the parent FDB entry. An RCU reader can find the parent during this interval. first_remote_rcu() then applies list_entry_rcu() to the empty list head, producing an invalid remote pointer that the receive learning path can read from and write to. When a matching remote is the sole remaining remote, leave it linked and ask the caller to destroy the entire FDB entry. vxlan_fdb_destroy() keeps the remote attached while sending the deletion notification and removing the parent from the lookup structures.
How severe is CVE-2026-80838?
Severity scoring for CVE-2026-80838 is pending analysis.
How do I fix CVE-2026-80838?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-80838?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST