Executive brief
A vulnerability in the Linux kernel's network bridging component could allow a local attacker to cause a system crash or potentially execute unauthorized actions. The issue occurs when the system is configured with Multiple Spanning Tree (MST) enabled and VLAN filtering disabled, leading to a memory error during network port deletion. This could impact the overall stability and availability of servers or networking equipment running affected versions of Linux.
Technical details
A use-after-free vulnerability exists in the Linux kernel bridge implementation (net/bridge) due to a race condition between FDB (Forwarding Database) learning and port deletion. When Multiple Spanning Tree (MST) is enabled, it can bypass the port's disabled state. If VLAN filtering is also disabled, FDB learning may continue even after a port's FDBs have been flushed and the port is being removed. This leads to a use-after-free when an expired FDB entry is subsequently deleted. The fix introduces a check for the port's VLAN group pointer (p->vlgrp), which is set to NULL during deletion, to ensure the MST state bypass does not occur during the teardown process.
Affected products
- Linux Linux Kernel 5.18 to 6.17.8, 6.12.58, 6.6.117, 6.1.159
Timeline
- 2025-11-05: patched: Initial fix commit by Nikolay Aleksandrov
- 2025-12-08: disclosed: CVE published
References
- https://git.kernel.org/stable/c/3b60ce334c1ce8b3fad7e02dcd5ed9f6646477c8
- https://git.kernel.org/stable/c/8dca36978aa80bab9d4da130c211db75c9e00048
- https://git.kernel.org/stable/c/991fbe1680cd41a5f97c92cd3a3496315df36e4b
- https://git.kernel.org/stable/c/bf3843183bc3158e5821b46f330c438ae9bd6ddb
- https://git.kernel.org/stable/c/e19085b2a86addccff33ab8536fc67ebd9d52198