๐Ÿ” CVE Alert

CVE-2026-74473

UNKNOWN 0.0

vxlan: use pskb_network_may_pull() in route_shortcircuit()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() in route_shortcircuit() route_shortcircuit() currently calls pskb_may_pull(skb, sizeof(struct iphdr)) (or ipv6hdr), which checks if bytes are available starting from skb->data. However, in vxlan_xmit(), skb->data points to the MAC header, so skb_network_offset(skb) is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, 20) only checks 20 bytes from skb->data (which is 14 bytes MAC header + 6 bytes of IP header), leaving the rest of the IP header potentially un-pulled in non-linear frags. Subsequent dereferences of ip_hdr(skb)->daddr can read beyond the pulled linear buffer length. Fix this by using pskb_network_may_pull(), which adds skb_network_offset(skb) to the length check to ensure the full network header is present in the linear buffer.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
e4f67addf158f98f8197e08974966b18480dc751 < 42887be7c4cf283cce02cd0fb6411221167c8b6c e4f67addf158f98f8197e08974966b18480dc751 < aa0d31376d574ac858a40078431a77127bf04ee4 e4f67addf158f98f8197e08974966b18480dc751 < ee799977d7941dbfb11049e17edd9eaf4f8820f7 e4f67addf158f98f8197e08974966b18480dc751 < 4f3f96e771a20263635bb5e1307c112d613b4bbd e4f67addf158f98f8197e08974966b18480dc751 < 26bb2dd0a8839617e2c79ffbbe1923f8e4bab9fb
Linux / Linux
3.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/42887be7c4cf283cce02cd0fb6411221167c8b6c git.kernel.org: https://git.kernel.org/stable/c/aa0d31376d574ac858a40078431a77127bf04ee4 git.kernel.org: https://git.kernel.org/stable/c/ee799977d7941dbfb11049e17edd9eaf4f8820f7 git.kernel.org: https://git.kernel.org/stable/c/4f3f96e771a20263635bb5e1307c112d613b4bbd git.kernel.org: https://git.kernel.org/stable/c/26bb2dd0a8839617e2c79ffbbe1923f8e4bab9fb