CVE-2026-68116
7.9Linux · Kernel
A vulnerability in the Linux kernel VXLAN Multicast Database (MDB) subsystem can lead to source list corruption during failed replace operations, potentially causing network traffic misrouting.
Executive summary
A high-severity flaw in the Linux kernel VXLAN MDB subsystem allows for potential network traffic manipulation and denial of service.
Vulnerability
The vulnerability exists in the VXLAN MDB subsystem, where failed replace operations lead to source list corruption. An authenticated local attacker can exploit this condition to cause traffic that should be blocked to be forwarded or vice versa, effectively undermining network segmentation.
Business impact
The ability to manipulate network traffic flows poses a severe risk to network security and data privacy. With a CVSS score of 7.9, this vulnerability could be utilized to bypass network access controls, leading to unauthorized data access or service disruption.
Remediation
Immediate Action: Update the Linux kernel to versions 6.6.148, 6.12.101, 6.18.42, 7.1.6, or later, to resolve the MDB corruption issue.
Proactive Monitoring: Monitor network traffic for unexpected routing behavior or anomalies in multicast traffic distribution.
Compensating Controls: Implement strict network access control lists and monitor for unauthorized changes to network configurations.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Organizations utilizing VXLAN for virtualized network infrastructure must treat this update with high priority. Patching the kernel is essential to prevent potential traffic interception or network-level denial of service attacks.