PT-2026-97937 · Linux · Linux Kernel

CVE-2026-93250

·

Published

2026-09-24

·

Updated

2026-09-28

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the vxlan mdb flush() function. The function iterates over Multicast Database (MDB) entries using hlist for each entry safe(), which is designed to handle the removal of the current entry but not subsequent entries in the list. When flushing remotes of a (, G) entry, the process can trigger the removal of (S, G) entries. If an (S, G) entry is located after the (, G) entry being processed, it may be freed prematurely. Consequently, the next iteration of the loop attempts to operate on the already freed entry, leading to a wild-memory-access. This condition can be triggered during device deletion or via RTM DELMDB with NLM F BULK.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-93250
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel