๐Ÿ” CVE Alert

CVE-2026-74473

CRITICAL 9.8

vxlan: use pskb_network_may_pull() in route_shortcircuit()

CVSS Score
9.8
EPSS Score
0.5%
EPSS Percentile
38th

In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() in route_shortcircuit() route_shortcircuit() currently calls pskb_may_pull(skb, sizeof(struct iphdr)) (or ipv6hdr), which checks if bytes are available starting from skb->data. However, in vxlan_xmit(), skb->data points to the MAC header, so skb_network_offset(skb) is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, 20) only checks 20 bytes from skb->data (which is 14 bytes MAC header + 6 bytes of IP header), leaving the rest of the IP header potentially un-pulled in non-linear frags. Subsequent dereferences of ip_hdr(skb)->daddr can read beyond the pulled linear buffer length. Fix this by using pskb_network_may_pull(), which adds skb_network_offset(skb) to the length check to ensure the full network header is present in the linear buffer.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Last Updated Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
e4f67addf158f98f8197e08974966b18480dc751 < c419af4924c1593500a40519730ed98575d04a3e e4f67addf158f98f8197e08974966b18480dc751 < 6bd0a3a1b5744166946f0c551a6665c3b46b05e4 e4f67addf158f98f8197e08974966b18480dc751 < 214ba43faf106cb06cd3dd30999c5c809c868b53 e4f67addf158f98f8197e08974966b18480dc751 < 42887be7c4cf283cce02cd0fb6411221167c8b6c e4f67addf158f98f8197e08974966b18480dc751 < aa0d31376d574ac858a40078431a77127bf04ee4 e4f67addf158f98f8197e08974966b18480dc751 < ee799977d7941dbfb11049e17edd9eaf4f8820f7 e4f67addf158f98f8197e08974966b18480dc751 < 4f3f96e771a20263635bb5e1307c112d613b4bbd e4f67addf158f98f8197e08974966b18480dc751 < 26bb2dd0a8839617e2c79ffbbe1923f8e4bab9fb
Linux / Linux
3.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c419af4924c1593500a40519730ed98575d04a3e git.kernel.org: https://git.kernel.org/stable/c/6bd0a3a1b5744166946f0c551a6665c3b46b05e4 git.kernel.org: https://git.kernel.org/stable/c/214ba43faf106cb06cd3dd30999c5c809c868b53 git.kernel.org: https://git.kernel.org/stable/c/42887be7c4cf283cce02cd0fb6411221167c8b6c git.kernel.org: https://git.kernel.org/stable/c/aa0d31376d574ac858a40078431a77127bf04ee4 git.kernel.org: https://git.kernel.org/stable/c/ee799977d7941dbfb11049e17edd9eaf4f8820f7 git.kernel.org: https://git.kernel.org/stable/c/4f3f96e771a20263635bb5e1307c112d613b4bbd git.kernel.org: https://git.kernel.org/stable/c/26bb2dd0a8839617e2c79ffbbe1923f8e4bab9fb