Impact
The vulnerability arises because firewall rules that encrypt VXLAN datagrams on Linux Swarm nodes treat any UDP packet that is destined for the Swarm data-path port and carries a VXLAN header for an encrypted overlay network as authentic, regardless of which process emitted it. This flaw allows a local user process to forge such packets, which the kernel then encrypts with the overlay‑network IPsec configuration and delivers to containers on the node. Consequently, an attacker can inject arbitrary network traffic into the overlay network, potentially compromising confidentiality, integrity, or availability of container services that share the same overlay.
Affected Systems
The issue affects Docker Engine, the Docker Engine overlay network driver, and the Moby overlay network driver on Linux hosts that participate in a Swarm cluster. Any node using the default overlay network configuration is vulnerable, because the data‑path port used for VXLAN encapsulation by the kernel is subject to the inappropriate rule.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The attack vector is local: a process running in the host network namespace can craft a VXLAN packet and send it to the data-path port. The firewall rule failure guarantees that the packet is encrypted and treated as valid by the kernel, delivering the forged payload into the overlay network. Once inside the network, the attacker gains the ability to reach any container in that overlay, compromising confidentiality and integrity of container traffic.
OpenCVE Enrichment