CVE-2026-68116

7.9

Linux · Kernel

A vulnerability in the Linux kernel VXLAN Multicast Database (MDB) subsystem can lead to source list corruption during failed replace operations, potentially causing network traffic misrouting.

Executive summary

A high-severity flaw in the Linux kernel VXLAN MDB subsystem allows for potential network traffic manipulation and denial of service.

Vulnerability

The vulnerability exists in the VXLAN MDB subsystem, where failed replace operations lead to source list corruption. An authenticated local attacker can exploit this condition to cause traffic that should be blocked to be forwarded or vice versa, effectively undermining network segmentation.

Business impact

The ability to manipulate network traffic flows poses a severe risk to network security and data privacy. With a CVSS score of 7.9, this vulnerability could be utilized to bypass network access controls, leading to unauthorized data access or service disruption.

Remediation

Immediate Action: Update the Linux kernel to versions 6.6.148, 6.12.101, 6.18.42, 7.1.6, or later, to resolve the MDB corruption issue.

Proactive Monitoring: Monitor network traffic for unexpected routing behavior or anomalies in multicast traffic distribution.

Compensating Controls: Implement strict network access control lists and monitor for unauthorized changes to network configurations.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Organizations utilizing VXLAN for virtualized network infrastructure must treat this update with high priority. Patching the kernel is essential to prevent potential traffic interception or network-level denial of service attacks.

More Linux CVEs