Vulnerability Intelligence Report
vxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-74475
In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() in route_shortcircuit() The neighbour hardware address n->ha can be updated asynchronously by the neighbour subsystem, protected by n->ha_lock seqlock. Reading n->ha without holding the seqlock loop can lead to torn reads or reading a partially updated MAC address. Use neigh_ha_snapshot() in route_shortcircuit() to safely copy n->ha under read_seqbegin()/read_seqretry() lock protection before using it. Note that arp_reduce() and neigh_reduce() seem to have the same issue left for future patches.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.0
EPSS Probability:0.40%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Linux | Linux | e4f67addf158f98f8197e08974966b18480dc751 < 32a9590a8d30426e3db63e6b20893e47e02576c0 (affected), e4f67addf158f98f8197e08974966b18480dc751 < d0993fc053f29e15cc7c9fe2029df3882a2ab5ab (affected), e4f67addf158f98f8197e08974966b18480dc751 < 87210054bad82bbae6f483a742dc45722fb47a6b (affected), e4f67addf158f98f8197e08974966b18480dc751 < d08e8ac13f2e228cc7fc3c70b5ebe71557b624a0 (affected), e4f67addf158f98f8197e08974966b18480dc751 < ec341bb76d77b4c2948764375ee6bfeef4bb41c3 (affected), e4f67addf158f98f8197e08974966b18480dc751 < ff89415d34c3ab9f5312316423122e664ed3524f (affected), e4f67addf158f98f8197e08974966b18480dc751 < 05f2987f73daa05333fd713d05546142f9f7c5f0 (affected), e4f67addf158f98f8197e08974966b18480dc751 < 8eca411347e1d38964f9ed2c8d3b6ab0e7e4473d (affected) |
| Linux | Linux | 3.8 (affected), 0 < 3.8 (unaffected), 5.10.265 <= 5.10.* (unaffected), 5.15.216 <= 5.15.* (unaffected), 6.1.183 <= 6.1.* (unaffected), 6.6.151 <= 6.6.* (unaffected), 6.12.103 <= 6.12.* (unaffected), 6.18.44 <= 6.18.* (unaffected), 7.1.8 <= 7.1.* (unaffected), 7.2 <= * (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.399%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | kernel.org · Vendor · USA |
| Reserved | 2026-08-15T05:44:03 |
| Published | 2026-08-15T12:27:10 |
| Last Updated | 2026-08-19T16:37:28 |
Community Chatter & Buzz