Use-after-free in Linux kernel - CVE-2026-93250
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to a use-after-free in vxlan_mdb_flush() when flushing VXLAN multicast database entries through RTM_DELMDB bulk requests. A local user can create an (S, G) entry before a (*, G) entry and issue a bulk RTM_DELMDB request to cause memory corruption.
The (*, G) entry must be added with NLM_F_REPLACE because adding the source otherwise fails with -EEXIST.
Affected software
How to mitigate CVE-2026-93250
External References
- https://git.kernel.org/stable/c/3e6b705bc162fc7257645725a7d2cf6c71250318
- https://git.kernel.org/stable/c/bc2dc66a6693a78f8c1e6ca2dbebd50f16e2c366
- https://git.kernel.org/stable/c/c7dc26d06f90ca11bbd6114f6a62a67d038816c7
- https://git.kernel.org/stable/c/f26400b325bdc2868e40612c4804c82cf8ba6275
- https://git.kernel.org/stable/c/f8a9b988e7a7bc674e74e8c901794d792c35689e