SB20260812426 - Improper control of a resource through its lifetime in Linux kernel net vxlan driver



SB20260812426 - Improper control of a resource through its lifetime in Linux kernel net vxlan driver

Published: August 12, 2026

Security Bulletin ID SB20260812426
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-68116)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass intended traffic filtering.

The vulnerability exists due to improper state management in vxlan multicast database remote source list handling when replacing the source list of an existing (*, G) remote entry. A local user can trigger a failed source list replacement to bypass intended traffic filtering.

An EXCLUDE filter may start forwarding traffic that should be blocked, while an INCLUDE filter may drop traffic that should be forwarded.


Remediation

Install update from vendor's website.