Description
In the Linux kernel, the following vulnerability has been resolved:

vxlan: fix reading neigh ha

Currently arp/neigh_reduce read neigh ha directly which can lead to
partial reads while the neigh is being updated. Use neigh_ha_snapshot to
take a stable snapshot of the address similar to route_shortcircuit which
already does the right thing.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Race condition leading to partial neighbor address reads potentially causing data inconsistency or service disruption
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises in the Linux kernel’s handling of virtual local area network (VXLAN) neighbor information. The existing arp/neigh_reduce routine reads the neighbor high‑address (neigh ha) directly while that structure may be concurrently updated by another kernel thread. This can lead to partial, out‑of‑date reads of the address, which in turn may cause incorrect neighbor resolution or subtle corruption of network state. The flaw is a classic data‑race condition that could undermine the integrity of the network stack and, if exploited, could lead to denial‑of‑service behaviors such as packet drops or network congestion. The kernel developers mitigated the issue by replacing the direct read with a stable snapshot obtained via neigh_ha_snapshot, mirroring the safeguards used in route_shortcircuit processing.

Affected Systems

All Linux kernel builds prior to the inclusion of the neigh_ha_snapshot fix are affected. The vendor list is limited to the Linux kernel itself; no specific distribution version range is provided, so any user deploying an unpatched kernel must consider the vulnerability present. It does not appear to be limited to a particular kernel release or configuration.

Risk and Exploitability

The EPSS score for this vulnerability is below 1%, indicating a very low probability of active exploitation at present. The flaw is not logged in CISA’s KEV catalog. The absence of a CVSS score in the supplied data means the severity can only be inferred from the nature of the race condition; however, potential impacts on network reliability suggest a moderate severity assessment. Because the flaw requires concurrent kernel activity on the same machine, an attacker would typically need local privilege or the ability to hijack kernel execution to trigger exploitation. Overall, while the risk is not negligible, it is unlikely to be widely exploited under current threat scenarios.

Generated by OpenCVE AI on September 20, 2026 at 03:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that incorporates the neigh_ha_snapshot fix
  • If immediate update is unavailable, monitor kernel mailing lists and security advisories for downstream patches or custom backports from the distribution
  • Consider applying temporary network isolation or disabling VXLAN interfaces if the vulnerability cannot be patched promptly for highly sensitive environments

Generated by OpenCVE AI on September 20, 2026 at 03:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-827

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: vxlan: fix reading neigh ha Currently arp/neigh_reduce read neigh ha directly which can lead to partial reads while the neigh is being updated. Use neigh_ha_snapshot to take a stable snapshot of the address similar to route_shortcircuit which already does the right thing.
Title vxlan: fix reading neigh ha
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:14.829Z

Reserved: 2026-09-11T19:38:34.786Z

Link: CVE-2026-90105

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:02.350

Modified: 2026-09-17T17:17:02.350

Link: CVE-2026-90105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:45:12Z

Weaknesses
  • CWE-827

    Improper Control of Document Type Definition