PT-2026-107622 · Docker · Docker

CVE-2026-92542

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Docker (affected versions not specified)
Description Firewall rules designed to mark VXLAN datagrams for encryption fail to distinguish between authentic datagrams sent from the kernel and forged datagrams sent by user processes. This allows any UDP datagram sent from the host network namespace of a Linux Swarm node to be encrypted using overlay-network IPsec parameters, provided the packet meets specific criteria: it must be a UDP datagram, the destination port must be the Swarm data-path port, and the datagram must start with a VXLAN header for the VNI (Virtual Network Identifier) of an encrypted overlay network connected to any running container on the node.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92542

Affected Products

Docker