DEBIAN-CVE-2026-74475
In the Linux kernel, the following vulnerability has been resolved: vxlan: use neighhasnapshot() in routeshortcircuit() The neighbour hardware address n->ha can be updated asynchronously by the neighbour subsystem, protected by n->halock seqlock. Reading n->ha without holding the seqlock loop can lead to torn reads or reading a partially updated MAC address. Use neighhasnapshot() in routeshortcircuit() to safely copy n->ha under readseqbegin()/readseqretry() lock protection before using it. Note that arpreduce() and neigh_reduce() seem to have the same issue left for future patches.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-74475