Impact
In the Linux kernel, vxlan processing code caches an IP header pointer, which can be invalidated when the packet buffer is altered by skb_tunnel_check_pmtu(). Reusing the stale pointer results in a use‑after‑free (CWE‑416, CWE‑825). The memory corruption can crash the system or, if attacker controls the freed region, enable arbitrary code execution.
Affected Systems
All Linux kernel builds that include VXLAN support are affected. The CPE list mentions kernels 7.1rc1 through 7.1rc5 as examples, indicating that any kernel with VXLAN enabled, including current mainstream releases, is at risk.
Risk and Exploitability
The CVSS score of 9.8 highlights severe impact, while the EPSS score of less than 1% suggests the exploitation probability is currently low. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need to send a crafted VXLAN packet to a host that has an active VXLAN interface; thus the attack surface is limited to systems with VXLAN enabled.
OpenCVE Enrichment
Ubuntu USN