Use-after-free in Linux kernel - CVE-2026-98023
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to use-after-free in the VXLAN forwarding database entry handling when configuring dynamic FDB entries that reference an FDB nexthop. A local user can configure dynamic entries on VXLAN devices that share an FDB nexthop to cause memory corruption.
The race can occur when an entry is aged while another device adds or deletes an entry associated with the shared FDB nexthop.