
🚨Critical - Linux kernel VXLAN unlocked neighbor MAC read → cross-tenant traffic leakage (CVE-2026-74475) route_shortcircuit() in drivers/net/vxlan/vxlan_core.c reads n->ha without the ha_lock seqlock, so ARP/NDP churn yields a torn MAC — on VXLAN VTEPs, remote traffic can force mis-encapsulation that redirects or leaks frames across tenants (CVSS 10.0). 👉Affected: Linux >= 3.8 | Upgrade to 6.6.151+, 6.12.103+, 6.18.44+ or 7.1.8+
Post summary
CVE‑2026‑74475 exposes a critical race in Linux kernel VXLAN leading to cross‑tenant traffic leakage; the post details the vulnerability and provides kernel upgrade recommendations.
