A vulnerability labeled as very critical has been found in Linux Kernel up to 6.18.43/7.1.7/7.2-rc5. The affected element is the function vxlan_xmit/arp_reduce/vxlan_mdb_entry_skb_get of the component vxlan. The manipulation results in improper input validation.

This vulnerability is reported as CVE-2026-74474. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.