{"api_version":"1","generated_at":"2026-08-22T04:27:11+00:00","cve":"CVE-2026-74474","urls":{"html":"https://cve.report/CVE-2026-74474","api":"https://cve.report/api/cve/CVE-2026-74474.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-74474","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-74474"},"summary":{"title":"vxlan: use pskb_network_may_pull() for transmit path header pulls","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: use pskb_network_may_pull() for transmit path header pulls\n\nIn vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was\nbeing called to verify the availability of network layer headers (ARP, IPv6/ND,\nIP/IPv6 MDB keys).\n\nHowever, during transmit skb->data points to the MAC header, so skb_network_offset(skb)\nis ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb->data\nrather than skb_network_offset(skb) + len, which can leave part of the network header\nin non-linear frags.\n\nReplace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly\naccount for the MAC header offset.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 13:17:52","updated_at":"2026-08-17 06:19:43"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/7076a34b6e33315dc160b4612bfea1c597495585","name":"https://git.kernel.org/stable/c/7076a34b6e33315dc160b4612bfea1c597495585","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b9553558b48db54ac9273e6b98d7263ef5c1a329","name":"https://git.kernel.org/stable/c/b9553558b48db54ac9273e6b98d7263ef5c1a329","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/94dee751aad627b3645d424b5d0c736d394573e9","name":"https://git.kernel.org/stable/c/94dee751aad627b3645d424b5d0c736d394573e9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-74474","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74474","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e4f67addf158f98f8197e08974966b18480dc751 94dee751aad627b3645d424b5d0c736d394573e9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e4f67addf158f98f8197e08974966b18480dc751 7076a34b6e33315dc160b4612bfea1c597495585 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e4f67addf158f98f8197e08974966b18480dc751 b9553558b48db54ac9273e6b98d7263ef5c1a329 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3.8","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 3.8 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.44 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.8 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"74474","cve":"CVE-2026-74474","epss":"0.004420000","percentile":"0.367700000","score_date":"2026-08-17","updated_at":"2026-08-18 00:11:46"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/net/vxlan/vxlan_core.c","drivers/net/vxlan/vxlan_mdb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"94dee751aad627b3645d424b5d0c736d394573e9","status":"affected","version":"e4f67addf158f98f8197e08974966b18480dc751","versionType":"git"},{"lessThan":"7076a34b6e33315dc160b4612bfea1c597495585","status":"affected","version":"e4f67addf158f98f8197e08974966b18480dc751","versionType":"git"},{"lessThan":"b9553558b48db54ac9273e6b98d7263ef5c1a329","status":"affected","version":"e4f67addf158f98f8197e08974966b18480dc751","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/net/vxlan/vxlan_core.c","drivers/net/vxlan/vxlan_mdb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"3.8"},{"lessThan":"3.8","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.44","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.8","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.44","versionStartIncluding":"3.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.8","versionStartIncluding":"3.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"3.8","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: use pskb_network_may_pull() for transmit path header pulls\n\nIn vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was\nbeing called to verify the availability of network layer headers (ARP, IPv6/ND,\nIP/IPv6 MDB keys).\n\nHowever, during transmit skb->data points to the MAC header, so skb_network_offset(skb)\nis ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb->data\nrather than skb_network_offset(skb) + len, which can leave part of the network header\nin non-linear frags.\n\nReplace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly\naccount for the MAC header offset."}],"metrics":[{"cvssV3_1":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:N - The bug is in VXLAN transmit handling reached when overlay/bridged traffic is sent through a VXLAN netdev; remote peers on cloud/Kubernetes/OpenStack overlay networks can inject ARP, ND, or multicast frames that traverse vxlan_xmit without local shell access.\nAC:L - Once a VXLAN device has proxy or MDB enabled, an attacker can reliably craft non-linear sk_buff frames (fragmented payloads with headers split across head/frags) to pass the undersized pskb_may_pull check and trigger out-of-bounds header reads.\nPR:N - Exploitation requires only the ability to send L2/L3 traffic on an existing VXLAN overlay; no host credentials, root, or CAP_NET_ADMIN on the victim are needed because any unauthenticated remote tenant VM, pod, or overlay peer can forward triggering frames into the transmit path.\nUI:N - No victim user action is required; the kernel processes attacker-supplied network frames automatically during normal overlay bridging and VXLAN encapsulation.\nS:U - Impact is confined to the kernel network stack on the affected host; it does not cross a VM, container, or hypervisor security boundary into a different authority.\nC:H - Undersized pskb_may_pull allows direct network-header pointer access past skb_headlen into non-linear frags or adjacent kernel memory, constituting an out-of-bounds kernel read capable of disclosing sensitive heap or packet-buffer contents.\nI:H - Out-of-bounds parsed ARP, ND, and IP header fields drive proxy neighbour replies and MDB multicast forwarding decisions, letting an attacker influence overlay neighbour resolution and traffic redirection on the victim node.\nA:H - Out-of-bounds header access in the atomic VXLAN transmit path can cause kernel oops or panic, and an unauthenticated remote attacker can trigger this repeatedly for denial of service against VXLAN-enabled infrastructure nodes."}]}],"providerMetadata":{"dateUpdated":"2026-08-17T05:47:35.265Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/94dee751aad627b3645d424b5d0c736d394573e9"},{"url":"https://git.kernel.org/stable/c/7076a34b6e33315dc160b4612bfea1c597495585"},{"url":"https://git.kernel.org/stable/c/b9553558b48db54ac9273e6b98d7263ef5c1a329"}],"title":"vxlan: use pskb_network_may_pull() for transmit path header pulls","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-74474","datePublished":"2026-08-15T12:27:10.037Z","dateReserved":"2026-08-15T05:44:03.903Z","dateUpdated":"2026-08-17T05:47:35.265Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 13:17:52","lastModifiedDate":"2026-08-17 06:19:43","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"74474","Ordinal":"1","Title":"vxlan: use pskb_network_may_pull() for transmit path header pull","CVE":"CVE-2026-74474","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"74474","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: use pskb_network_may_pull() for transmit path header pulls\n\nIn vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was\nbeing called to verify the availability of network layer headers (ARP, IPv6/ND,\nIP/IPv6 MDB keys).\n\nHowever, during transmit skb->data points to the MAC header, so skb_network_offset(skb)\nis ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb->data\nrather than skb_network_offset(skb) + len, which can leave part of the network header\nin non-linear frags.\n\nReplace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly\naccount for the MAC header offset.","Type":"Description","Title":"vxlan: use pskb_network_may_pull() for transmit path header pull"}]}}}