{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f"
            },
            {
              "fixed": "2a7c2f00843225d5f037676bca649321f3d024c7"
            },
            {
              "fixed": "a8820c8a7718327e96849782033e7c85a0f6bcfe"
            },
            {
              "fixed": "8ba68fd6cdd1e3c92b92f25c7e48bf7bd51a183c"
            },
            {
              "fixed": "4bbc76ee1b21d3bd045d6d819b2bacd30a6372ab"
            },
            {
              "fixed": "d5d4a7b538b52db63927773a8905fcd9f78a42e2"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.108"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.49"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.1.13"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "7.2.0"
            },
            {
              "fixed": "7.2.3"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80838.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: keep the last remote linked during FDB flush\n\nA non-nexthop FDB entry is expected to have at least one remote while it\nremains reachable through the FDB hash table. A filtered bulk flush\nviolates this invariant when every remote matches: It unlinks the last\nremote in vxlan_fdb_dst_destroy() and only afterwards tells vxlan_flush()\nto destroy the parent FDB entry.\n\nAn RCU reader can find the parent during this interval.\nfirst_remote_rcu() then applies list_entry_rcu() to the empty list head,\nproducing an invalid remote pointer that the receive learning path can\nread from and write to.\n\nWhen a matching remote is the sole remaining remote, leave it linked and\nask the caller to destroy the entire FDB entry. vxlan_fdb_destroy() keeps\nthe remote attached while sending the deletion notification and removing\nthe parent from the lookup structures.",
  "id": "CVE-2026-80838",
  "modified": "2026-09-06T03:30:59.038929475Z",
  "published": "2026-09-04T15:54:48.371Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/2a7c2f00843225d5f037676bca649321f3d024c7"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/4bbc76ee1b21d3bd045d6d819b2bacd30a6372ab"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/8ba68fd6cdd1e3c92b92f25c7e48bf7bd51a183c"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/a8820c8a7718327e96849782033e7c85a0f6bcfe"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d5d4a7b538b52db63927773a8905fcd9f78a42e2"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80838.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80838"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "vxlan: keep the last remote linked during FDB flush"
}