Race condition in Linux kernel - CVE-2026-90105
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause partial reads of neighbor hardware addresses.
The vulnerability exists due to a race condition in the VXLAN arp_reduce and neigh_reduce functions when processing ARP or IPv6 neighbor-discovery traffic during a neighbor hardware-address update. A remote attacker can send network traffic to cause partial reads of neighbor hardware addresses.