7.8
CVE-2026-64032
- EPSS 0.13%
- Veröffentlicht 19.07.2026 15:39:22
- Zuletzt bearbeitet 30.07.2026 14:59:47
- CVE-Watchlists
- Unerledigt
bridge: mcast: Fix a possible use-after-free when removing a bridge port
In the Linux kernel, the following vulnerability has been resolved:
bridge: mcast: Fix a possible use-after-free when removing a bridge port
When per-VLAN multicast snooping is enabled, the bridge iterates over
all the bridge ports, disables the per-port multicast context on each
port and enables the per-{port, VLAN} multicast contexts instead. The
reverse happens when per-VLAN multicast snooping is disabled.
When global multicast snooping is enabled, the bridge iterates over all
the bridge ports and enables the per-port multicast context on each
port. The reverse happens when multicast snooping is disabled.
The above scheme can result in a situation where both types of contexts
(per-port and per-{port, VLAN}) are enabled on a single bridge port:
# ip link add name br1 up type bridge mcast_snooping 1 mcast_querier 1 vlan_filtering 1
# ip link add name dummy1 up master br1 type dummy
# ip link set dev br1 type bridge mcast_vlan_snooping 1
# ip link set dev br1 type bridge mcast_snooping 0
# ip link set dev br1 type bridge mcast_snooping 1
This is not intended and it is a problem since the commit cited below.
Prior to this commit, when removing a bridge port,
br_multicast_disable_port() would disable the per-port multicast context
and the per-{port, VLAN} multicast contexts would get disabled when
flushing VLANs.
After this commit, br_multicast_disable_port() only disables the
per-port multicast context if per-VLAN multicast snooping is disabled.
If both types of contexts were enabled on the port when it was removed,
the per-port multicast context would remain enabled when freeing the
bridge port, leading to a use-after-free [1].
Fix by preventing the bridge from enabling / disabling the per-port
multicast contexts when toggling global multicast snooping if per-VLAN
multicast snooping is enabled.
[1]
ODEBUG: free active (active state 0) object: ffff88810f8bda78 object type: timer_list hint: br_ip6_multicast_port_query_expired (net/bridge/br_multicast.c:1927)
WARNING: lib/debugobjects.c:629 at debug_print_object+0x1b1/0x3e0, CPU#5: swapper/5/0
[...]
Call Trace:
<IRQ>
__debug_check_no_obj_freed (lib/debugobjects.c:1116)
kfree (mm/slub.c:2620 mm/slub.c:6250 mm/slub.c:6565)
kobject_cleanup (lib/kobject.c:689)
rcu_do_batch (kernel/rcu/tree.c:2617)
rcu_core (kernel/rcu/tree.c:2869)
handle_softirqs (kernel/softirq.c:622)
__irq_exit_rcu (kernel/softirq.c:656 kernel/softirq.c:496 kernel/softirq.c:735)
irq_exit_rcu (kernel/softirq.c:752)
sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1061 (discriminator 47) arch/x86/kernel/apic/apic.c:1061 (discriminator 47))
</IRQ>Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
410a033bfa8c7daefbae0225c836693db2149ec1
Version <
ddefd1b8e5eb58933a697ab38334f0fd82e7fb8b
Status
affected
Version
c6d16eab122744df698f18b47cf771945cd55066
Version <
ed3b69e60385a03df11c6d12e5d7bdf0f4a11b70
Status
affected
Version
b4c83b37490d61cfdd62a2b29e98a9b89004b5c0
Version <
1900ca8acb92fbea8bf9abef9927c7fed03db7fc
Status
affected
Version
78f768e36c065ca3f88272fcf39014782c2d4ecd
Version <
ebe5561154c823b323bd06e350b55e0b8604d851
Status
affected
Version
4b30ae9adb047dd0a7982975ec3933c529537026
Version <
a9224862d597d0eed0a34bbb27343f703fc4113f
Status
affected
Version
4b30ae9adb047dd0a7982975ec3933c529537026
Version <
7213256c91ed778a0997c2029c152b18dc50e4fd
Status
affected
Version
4b30ae9adb047dd0a7982975ec3933c529537026
Version <
4df78ff02629c7729168f0696a7a2123c389818d
Status
affected
Version
c996e25df0b3282c724bb5aca434518bc08cd963
Status
affected
Version
5.15.186
Version <
5.15.209
Status
affected
Version
6.1.142
Version <
6.1.175
Status
affected
Version
6.6.95
Version <
6.6.142
Status
affected
Version
6.12.35
Version <
6.12.92
Status
affected
Version
6.15.4
Version <
6.16
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.16
Status
affected
Version
0
Version <
6.16
Status
unaffected
Version <=
5.15.*
Version
5.15.209
Status
unaffected
Version <=
6.1.*
Version
6.1.175
Status
unaffected
Version <=
6.6.*
Version
6.6.142
Status
unaffected
Version <=
6.12.*
Version
6.12.92
Status
unaffected
Version <=
6.18.*
Version
6.18.34
Status
unaffected
Version <=
7.0.*
Version
7.0.11
Status
unaffected
Version <=
*
Version
7.1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.026 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/ddefd1b8e5eb58933a697ab38334f0fd82e7fb8b
https://git.kernel.org/stable/c/ed3b69e60385a03df11c6d12e5d7bdf0f4a11b70
https://git.kernel.org/stable/c/1900ca8acb92fbea8bf9abef9927c7fed03db7fc
https://git.kernel.org/stable/c/ebe5561154c823b323bd06e350b55e0b8604d851
https://git.kernel.org/stable/c/a9224862d597d0eed0a34bbb27343f703fc4113f
https://git.kernel.org/stable/c/7213256c91ed778a0997c2029c152b18dc50e4fd
https://git.kernel.org/stable/c/4df78ff02629c7729168f0696a7a2123c389818d