{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  vxlan: initialize _md in vxlan_xmit_one()  If a VXLAN device is configured with both VXLAN_F_COLLECT_METADATA and VXLAN_F_GBP, and a packet is transmitted through it using an external ip_tunnel_info that lacks the IP_TUNNEL_VXLAN_OPT_BIT flag, md is left pointing to the uninitialized _md stack variable:                  if (test_bit(IP_TUNNEL_VXLAN_OPT_BIT, info-\u003ekey.tun_flags)) {                         if (info-\u003eoptions_len \u003c sizeof(*md))                                 goto drop;                         md = ip_tunnel_info_opts(info);                 }  Because IP_TUNNEL_VXLAN_OPT_BIT is not set, md is not updated and remains pointing to _md. Later, vxlan_build_skb() is called with md, which eventually calls vxlan_build_gbp_hdr():          if (vxflags \u0026 VXLAN_F_GBP)                 vxlan_build_gbp_hdr(vxh, md);  Inside vxlan_build_gbp_hdr(), md-\u003egbp is read:          if (!md-\u003egbp)                 return;         gbp = (struct vxlanhdr_gbp *)vxh;         ...         if (md-\u003egbp \u0026 VXLAN_GBP_DONT_LEARN)                 gbp-\u003edont_learn = 1;  If the stack contains garbage, this causes: 1) VXLAN_HF_GBP flag to be spuriously set in the VXLAN header. 2) gbp-\u003edont_learn and gbp-\u003epolicy_applied to be set from stack bits. 3) gbp-\u003epolicy_id to receive 16 bits of uninitialized kernel stack data,    leaking it onto the wire.  Fix this by zero-initializing _md. If IP_TUNNEL_VXLAN_OPT_BIT is not present, md-\u003egbp remains 0, and vxlan_build_gbp_hdr() returns early without modifying the VXLAN header.",
  "id": "DEBIAN-CVE-2026-97965",
  "modified": "2026-09-26T04:47:39.983861359Z",
  "published": "2026-09-25T11:17:24.293Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-97965"
    }
  ],
  "upstream": [
    "CVE-2026-97965"
  ]
}