From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9AEEB3EB0FB for ; Sat, 15 Aug 2026 12:28:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786796940; cv=none; b=qGyhvRwrmLF2aG3ov3IectLvSdXlGvS92C2gQgGraKR/d5lHPPxSagVDEgO3dsSHLEvntMqjL8aag7RyUKjtdddGtNbxETZrLD8YMIEXgWjThRxulezwVTC3TGGDFZEovHg8liTa9+Ub9kwZGFI+/qiZv48aDJcey+3GlCeD0j4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786796940; c=relaxed/simple; bh=sAB/KLfAq/vhRTLGp09xrF+8CcD0mR/qNHHe9S76pzU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=EhfspuDsXKja926j5F4to7GEn6SW64o8Z5TVQkSUMQFAiI45h4ZI2CUxSsZmGj1ykKlsBf6CKoSnBODBLJCJzZ1iRBCpZ0qeHft+KFlprizhy433Kjs7JmPTTiQoeJtEk4gk/5dnpoboBIVGKJLl2XF5MMZCXhbO6TdopMt7Z0U= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=M+0oTycD; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="M+0oTycD" Received: by smtp.kernel.org (Postfix) with ESMTPSA id BD75A1F000E9; Sat, 15 Aug 2026 12:28:58 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1786796939; bh=OBvSYYuL7z49Pm6Ds35v/eKzZTYaSDvNF6QIyFBO4F4=; h=From:To:Cc:Subject:Date:Reply-To; b=M+0oTycDX4zn2LkyqxRoSwtGF/dvLdU/uhL8PlcBlzfqUlMbsGp66Qm6BEHaQizQO VmPfQYKqJQoTcE0+bXHztTpQhnTUsxD54S2pvaelgmtr9f7AnuPO/RCFLS2igm5ZzK AJeQkMDRLreukDNmodQLZMjiVMnHktU7tWwYUL78= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-74475: vxlan: use neigh_ha_snapshot() in route_shortcircuit() Date: Sat, 15 Aug 2026 21:25:56 +0900 Message-ID: <2026081535-CVE-2026-74475-a303@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2940; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=2jJhEPJ6hv0CGlwQWT6mIBcH1DilqeEszq145cONxGg=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkNUfuPbPM1ntoU15f0Xr44a8up43/dz/51N+C9t29a0 PZ33LUlHbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjCRtH6GBb0G8V26Hjf2X/4+ I+uCsvLdg3x8WQwLtkx9tP5VjdmjXzLR/7bfZ7l47n+BLAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() in route_shortcircuit() The neighbour hardware address n->ha can be updated asynchronously by the neighbour subsystem, protected by n->ha_lock seqlock. Reading n->ha without holding the seqlock loop can lead to torn reads or reading a partially updated MAC address. Use neigh_ha_snapshot() in route_shortcircuit() to safely copy n->ha under read_seqbegin()/read_seqretry() lock protection before using it. Note that arp_reduce() and neigh_reduce() seem to have the same issue left for future patches. The Linux kernel CVE team has assigned CVE-2026-74475 to this issue. Affected and fixed versions =========================== Issue introduced in 3.8 with commit e4f67addf158f98f8197e08974966b18480dc751 and fixed in 6.6.151 with commit d08e8ac13f2e228cc7fc3c70b5ebe71557b624a0 Issue introduced in 3.8 with commit e4f67addf158f98f8197e08974966b18480dc751 and fixed in 6.12.103 with commit ec341bb76d77b4c2948764375ee6bfeef4bb41c3 Issue introduced in 3.8 with commit e4f67addf158f98f8197e08974966b18480dc751 and fixed in 6.18.44 with commit ff89415d34c3ab9f5312316423122e664ed3524f Issue introduced in 3.8 with commit e4f67addf158f98f8197e08974966b18480dc751 and fixed in 7.1.8 with commit 05f2987f73daa05333fd713d05546142f9f7c5f0 Issue introduced in 3.8 with commit e4f67addf158f98f8197e08974966b18480dc751 and fixed in 7.2-rc6 with commit 8eca411347e1d38964f9ed2c8d3b6ab0e7e4473d Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74475 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/net/vxlan/vxlan_core.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/d08e8ac13f2e228cc7fc3c70b5ebe71557b624a0 https://git.kernel.org/stable/c/ec341bb76d77b4c2948764375ee6bfeef4bb41c3 https://git.kernel.org/stable/c/ff89415d34c3ab9f5312316423122e664ed3524f https://git.kernel.org/stable/c/05f2987f73daa05333fd713d05546142f9f7c5f0 https://git.kernel.org/stable/c/8eca411347e1d38964f9ed2c8d3b6ab0e7e4473d