Executive brief
A vulnerability in the Linux kernel's VXLAN networking component could allow an attacker to crash the system. VXLAN is a technology used to create virtual networks over physical infrastructure, often in data centers. By sending specific network traffic, an attacker can trigger a system failure, leading to a complete service outage.
Technical details
A NULL pointer dereference (NPD) exists in the vxlan_snoop() function of the Linux kernel's VXLAN driver. When MAC learning is enabled, an incoming packet may attempt to refresh an FDB entry that points to a nexthop object rather than a remote destination. The code incorrectly attempts to dereference a remote destination pointer that does not exist for nexthop-based entries. This can be triggered remotely by sending packets that target these specific FDB entries, resulting in a kernel panic (DoS). The issue has been resolved by ensuring packets targeting nexthop-based FDB entries are dropped before the invalid dereference occurs.
Affected products
- Linux Linux Kernel 5.8 to 6.12.46, 6.16.6, 6.17
Timeline
- 2025-09-01: patched: Initial fix commit authored
- 2025-09-19: disclosed: CVE published