SB20260812426 - Improper control of a resource through its lifetime in Linux kernel net vxlan driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-68116)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass intended traffic filtering.
The vulnerability exists due to improper state management in vxlan multicast database remote source list handling when replacing the source list of an existing (*, G) remote entry. A local user can trigger a failed source list replacement to bypass intended traffic filtering.
An EXCLUDE filter may start forwarding traffic that should be blocked, while an INCLUDE filter may drop traffic that should be forwarded.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2c54dff57606590fa4abec46bab6bea3133f1539
- https://git.kernel.org/stable/c/54a3c27b357dfb34f327f89bfadeb998bef8051e
- https://git.kernel.org/stable/c/5bc8fc1d2ff802eec839e03adef5df597421898d
- https://git.kernel.org/stable/c/79370b573e92e8f190eb5f9a511fa5398340d8b2
- https://git.kernel.org/stable/c/dcd9b465965422b9654f6026e8a2fa8984f74c3c