SB20260928183 - Use-after-free in Linux kernel selftests net
Published: September 28, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-98023)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to use-after-free in the VXLAN forwarding database entry handling when configuring dynamic FDB entries that reference an FDB nexthop. A local user can configure dynamic entries on VXLAN devices that share an FDB nexthop to cause memory corruption.
The race can occur when an entry is aged while another device adds or deletes an entry associated with the shared FDB nexthop.
Remediation
Install update from vendor's website.