---
id: CVE-2026-98122
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()

  vxlan_mdb_is_valid_source(), which validates MDBE_ATTR_SOURCE and every
  MDBE_ATTR_SRC_LIST member, accepts…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()

  vxlan_mdb_is_valid_source(), which validates MDBE_ATTR_SOURCE and every
  MDBE_ATTR_SRC_LIST member, accepts…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= a3a48de5eade770e911d35291217bdd69ce04ef1 <
    e12c903fd13c6261b98ca18d8f70ac26e739e2f8
  - >-
    Linux >= a3a48de5eade770e911d35291217bdd69ce04ef1 <
    74e2a56c82209b0335b53e25f19f9b0590e2483d
  - >-
    Linux >= a3a48de5eade770e911d35291217bdd69ce04ef1 <
    71203a41d6fa2fa0ea2f3a7541987958bd3694fd
  - >-
    Linux >= a3a48de5eade770e911d35291217bdd69ce04ef1 <
    4aa61c88b4e292e10abdfd791334b8272108d68a
  - Linux 6.4
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T15:18:06.580'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98122'
references:
  - url: 'https://git.kernel.org/stable/c/4aa61c88b4e292e10abdfd791334b8272108d68a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/71203a41d6fa2fa0ea2f3a7541987958bd3694fd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/74e2a56c82209b0335b53e25f19f9b0590e2483d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e12c903fd13c6261b98ca18d8f70ac26e739e2f8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.820Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()

vxlan_mdb_is_valid_source(), which validates MDBE_ATTR_SOURCE and every
MDBE_ATTR_SRC_LIST member, accepts the all-zeros address.

A source list is only accepted on a (*, G) entry, whose source is the
all-zeros address, and for each member of the list an (S, G) entry is
derived from it by substituting the source. Entries are keyed by a plain
memcmp() of struct vxlan_mdb_entry_key, so if MDBE_ATTR_SOURCE is present
and holds the all-zeros address and the source list holds it as well, the
derived (S, G) key is byte-identical to the (*, G) key and resolves to the
same entry. Omitting MDBE_ATTR_SOURCE is not equivalent, as the key is
then left with a zero address family.

vxlan_mdb_remote_src_del() removes the forwarding entry of a source before
freeing the source entry:

	vxlan_mdb_remote_src_fwd_del(vxlan, group, remote, &ent->addr);
	vxlan_mdb_remote_src_entry_del(ent);

With the keys aliased, the first call deletes the remote of the entry that
owns 'ent' instead of a separate (S, G) entry, and frees 'ent'. The second
call then runs on the freed entry, and its hlist_del() reads ->pprev and
->next out of it and writes through them.

Adding the (*, G) entry with NLM_F_REPLACE and no source list marks the
all-zeros source for deletion and reaches this from the sweep at the end
of vxlan_mdb_remote_srcs_replace().

  BUG: KASAN: slab-use-after-free in __vxlan_mdb_add+0x1cd/0xd70
  Read of size 8 at addr ffff888102852500 by task poc/84
   __vxlan_mdb_add+0x1cd/0xd70
   vxlan_mdb_add+0xc0/0x140
   rtnl_mdb_add+0x157/0x2a0
   rtnetlink_rcv_msg+0x207/0x5a0
  Allocated by task 84:
   __kmalloc_cache_noprof+0x153/0x360
   vxlan_mdb_remote_srcs_add+0x2eb/0x440
   __vxlan_mdb_add+0x803/0xd70
  Freed by task 84:
   kfree+0x14c/0x3b0
   vxlan_mdb_remote_del+0x129/0x1a0
   __vxlan_mdb_del+0x4f/0xe0
   vxlan_mdb_remote_src_fwd_del.isra.0+0x162/0x1b0
   __vxlan_mdb_add+0x1c5/0xd70

The MDB operations are netns-scoped, so an unprivileged user can perform
them in a new user and network namespace.

Reject the all-zeros address in vxlan_mdb_is_valid_source(), which covers
both call sites. A (*, G) entry is expressed by omitting the source, so
nothing legitimate is refused.

Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
