SB20260928183 - Use-after-free in Linux kernel selftests net



SB20260928183 - Use-after-free in Linux kernel selftests net

Published: September 28, 2026 Updated: September 30, 2026

Security Bulletin ID SB20260928183
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Use-after-free (CVE-ID: CVE-2026-98023)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to use-after-free in the VXLAN forwarding database entry handling when configuring dynamic FDB entries that reference an FDB nexthop. A local user can configure dynamic entries on VXLAN devices that share an FDB nexthop to cause memory corruption.

The race can occur when an entry is aged while another device adds or deletes an entry associated with the shared FDB nexthop.


Remediation

Install update from vendor's website.