Executive brief
The Linux kernel's VXLAN networking driver contains a race condition when reading neighbor hardware addresses during ARP and IPv6 neighbor discovery processing. An attacker with local network access could exploit this to cause inconsistent neighbor address snapshots, potentially leading to packet misrouting or network service disruption in environments using VXLAN overlays.
Technical details
The vulnerability is a data race (CWE-362) in the VXLAN driver's arp_reduce() and neigh_reduce() functions in drivers/net/vxlan/vxlan_core.c. These functions read the neighbor hardware address (neigh->ha) directly without synchronization, allowing partial reads while the neighbor entry is being updated concurrently. An attacker on the same network segment can trigger neighbor updates via crafted ARP or IPv6 neighbor solicitation packets, causing inconsistent address snapshots to be used in subsequent lookups and address operations. The fix uses neigh_ha_snapshot() to safely capture a stable copy of the hardware address. The vulnerability affects VXLAN deployments that process ARP reduction (RFC 7348) or IPv6 proxy scenarios. No specific privilege escalation or code execution capability is described.
Affected products
- Linux Linux kernel Multiple versions (see kernel.org stable branches)
Timeline
- 2026-09-17: disclosed
- 2026-08-20: patched: Upstream fix committed; stable backports released 2026-09-14 onwards