CVE-2026-74475
In the Linux kernel, the following vulnerability has been resolved:
vxlan: use neighhasnapshot() in route_shortcircuit()
The neighbour hardware address n->ha can be updated asynchronously by the
neighbour subsystem, protected by n->ha_lock seqlock. Reading n->ha without
holding the seqlock loop can lead to torn reads or reading a partially updated
MAC address.
Use neighhasnapshot() in route_shortcircuit() to safely copy n->ha under
readseqbegin()/readseqretry() lock protection before using it.
Note that arpreduce() and neighreduce() seem to have the same issue
left for future patches.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/05f2987f73daa05333fd713d05546142f9f7c5f0, https://git.kernel.org/stable/c/32a9590a8d30426e3db63e6b20893e47e02576c0, https://git.kernel.org/stable/c/87210054bad82bbae6f483a742dc45722fb47a6b, https://git.kernel.org/stable/c/8eca411347e1d38964f9ed2c8d3b6ab0e7e4473d, https://git.kernel.org/stable/c/d08e8ac13f2e228cc7fc3c70b5ebe71557b624a0, https://git.kernel.org/stable/c/d0993fc053f29e15cc7c9fe2029df3882a2ab5ab, https://git.kernel.org/stable/c/ec341bb76d77b4c2948764375ee6bfeef4bb41c3, https://git.kernel.org/stable/c/ff89415d34c3ab9f5312316423122e664ed3524f, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74475.json, https://nvd.nist.gov/vuln/detail/CVE-2026-74475, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git