Description
The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace of a Linux Swarm node is encrypted with the overlay-network IPsec parameters which meets the following criteria:

- UDP datagram
- Destination port is the Swarm data-path port
- Datagram starts with a VXLAN header for the VNI of an encrypted overlay network which any running container on the node is connected to
Published: 2026-10-07
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized network injection into Docker Swarm overlay networks
Action: Apply Workaround
AI Analysis

Impact

The vulnerability arises because firewall rules that encrypt VXLAN datagrams on Linux Swarm nodes treat any UDP packet that is destined for the Swarm data-path port and carries a VXLAN header for an encrypted overlay network as authentic, regardless of which process emitted it. This flaw allows a local user process to forge such packets, which the kernel then encrypts with the overlay‑network IPsec configuration and delivers to containers on the node. Consequently, an attacker can inject arbitrary network traffic into the overlay network, potentially compromising confidentiality, integrity, or availability of container services that share the same overlay.

Affected Systems

The issue affects Docker Engine, the Docker Engine overlay network driver, and the Moby overlay network driver on Linux hosts that participate in a Swarm cluster. Any node using the default overlay network configuration is vulnerable, because the data‑path port used for VXLAN encapsulation by the kernel is subject to the inappropriate rule.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The attack vector is local: a process running in the host network namespace can craft a VXLAN packet and send it to the data-path port. The firewall rule failure guarantees that the packet is encrypted and treated as valid by the kernel, delivering the forged payload into the overlay network. Once inside the network, the attacker gains the ability to reach any container in that overlay, compromising confidentiality and integrity of container traffic.

Generated by OpenCVE AI on October 8, 2026 at 01:50 UTC.

Remediation

Vendor Workaround

Block userspace processes from sending UDP packets to the Swarm data-path port. iptables -I OUTPUT -p udp --dport "$(docker info --format '{{.Swarm.Cluster.DataPathPort}}')" -m owner --socket-exists -j DROP


OpenCVE Recommended Actions

  • Insert the following iptables rule to drop user space UDP packets to the Swarm data‑path port: iptables -I OUTPUT -p udp --dport "$(docker info --format '{{.Swarm.Cluster.DataPathPort}}')" -m owner --socket-exists -j DROP
  • Upgrade Docker Engine and the Moby overlay network driver to the latest patched releases as soon as they are available
  • Restrict the data-path port so that only privileged kernel processes are allowed to send UDP traffic, and remediate any existing firewall configurations that permit untrusted userspace processes to transmit to that port

Generated by OpenCVE AI on October 8, 2026 at 01:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Important


Thu, 08 Oct 2026 00:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-284

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-284

Wed, 07 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace of a Linux Swarm node is encrypted with the overlay-network IPsec parameters which meets the following criteria: - UDP datagram - Destination port is the Swarm data-path port - Datagram starts with a VXLAN header for the VNI of an encrypted overlay network which any running container on the node is connected to
Title Blind VXLAN injection into encrypted overlay networks from cluster peer
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published:

Updated: 2026-10-07T20:30:49.884Z

Reserved: 2026-09-16T13:00:30.172Z

Link: CVE-2026-92542

cve-icon Vulnrichment

Updated: 2026-10-07T20:30:44.871Z

cve-icon NVD

Status : Received

Published: 2026-10-07T17:17:02.580

Modified: 2026-10-07T21:17:21.650

Link: CVE-2026-92542

cve-icon Redhat

Severity : Important

Publid Date: 2026-10-07T16:42:20Z

Links: CVE-2026-92542 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T02:00:07Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-346

    Origin Validation Error