CVE-2026-90106

Summary

In the Linux kernel, the following vulnerability has been resolved:

net: bridge: arp/nd proxy: fix reading neigh ha

Currently neigh ha address is read directly, but that can result in torn/partial reads if the neigh is being updated. Use neigh_ha_snapshot to take a stable snapshot of the address.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux057658cb33fbf4d4309f01fe8845903b1cd07fad < 291c9e137b7c74e8a512cded4845352da4c4addaaffected
LinuxLinux057658cb33fbf4d4309f01fe8845903b1cd07fad < 57549ab9079122991dfa0f8248ca00e101e8e69baffected
LinuxLinux4.15affected
LinuxLinux0 < 4.15unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References