DEBIAN-CVE-2026-80681
In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after routeshortcircuit() Before routeshortcircuit(), the eth header pointer is cached from ethhdr(skb). Inside routeshortcircuit(), pskbmaypull() can be called, which may reallocate skb->head. In this case, returning to vxlanxmit() leaves the cached eth pointer pointing to freed memory, leading to a use-after-free when dereferencing eth->hdest. Fix this by updating eth = ethhdr(skb) after calling routeshortcircuit().
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-80681