Race condition in Linux kernel - CVE-2026-90106
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause incorrect ARP or neighbor discovery proxy responses.
The vulnerability exists due to a race condition in the Linux bridge ARP and neighbor discovery proxy handling when processing proxy requests while a neighbor entry is being updated. A remote attacker can send ARP or neighbor discovery requests during a concurrent neighbor update to cause incorrect ARP or neighbor discovery proxy responses.