A vulnerability marked as critical has been reported in Linux Kernel up to 6.1.177/6.6.144/6.12.96/6.18.39/7.1.4. Impacted is the function vxlan_gro_prepare_receive of the component vxlan. This manipulation causes null pointer dereference.

This vulnerability appears as CVE-2026-74406. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.