{"id":"CVE-2026-80838","summary":"vxlan: keep the last remote linked during FDB flush","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: keep the last remote linked during FDB flush\n\nA non-nexthop FDB entry is expected to have at least one remote while it\nremains reachable through the FDB hash table. A filtered bulk flush\nviolates this invariant when every remote matches: It unlinks the last\nremote in vxlan_fdb_dst_destroy() and only afterwards tells vxlan_flush()\nto destroy the parent FDB entry.\n\nAn RCU reader can find the parent during this interval.\nfirst_remote_rcu() then applies list_entry_rcu() to the empty list head,\nproducing an invalid remote pointer that the receive learning path can\nread from and write to.\n\nWhen a matching remote is the sole remaining remote, leave it linked and\nask the caller to destroy the entire FDB entry. vxlan_fdb_destroy() keeps\nthe remote attached while sending the deletion notification and removing\nthe parent from the lookup structures.","modified":"2026-09-06T03:46:52.336570451Z","published":"2026-09-04T15:54:48.371Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80838.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/2a7c2f00843225d5f037676bca649321f3d024c7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4bbc76ee1b21d3bd045d6d819b2bacd30a6372ab"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8ba68fd6cdd1e3c92b92f25c7e48bf7bd51a183c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a8820c8a7718327e96849782033e7c85a0f6bcfe"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d5d4a7b538b52db63927773a8905fcd9f78a42e2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80838.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80838"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f"},{"fixed":"2a7c2f00843225d5f037676bca649321f3d024c7"},{"fixed":"a8820c8a7718327e96849782033e7c85a0f6bcfe"},{"fixed":"8ba68fd6cdd1e3c92b92f25c7e48bf7bd51a183c"},{"fixed":"4bbc76ee1b21d3bd045d6d819b2bacd30a6372ab"},{"fixed":"d5d4a7b538b52db63927773a8905fcd9f78a42e2"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80838.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.108"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.49"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.13"}]},{"type":"ECOSYSTEM","events":[{"introduced":"7.2.0"},{"fixed":"7.2.3"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80838.json"}}],"schema_version":"1.9.0"}