Executive brief
A vulnerability was identified in the Linux kernel's network bridge component, which manages how different network segments communicate. Under certain conditions, the system could attempt to perform a 'sleep' operation while holding a lock that requires immediate, uninterrupted execution. This mismatch can lead to system instability or crashes (kernel panics), potentially causing a denial of service for the affected server.
Technical details
The vulnerability arises in the br_setport() function within the bridge netlink configuration path. Historically, br_setport() was called while holding the bridge spinlock (an atomic context). However, modern iterations of this function call dev_set_promiscuity(), which is a sleeping function. When certain bridge port flags are changed via netlink, the kernel attempts to sleep while holding the spinlock, triggering a 'scheduling while atomic' bug. This can result in a kernel splat or panic. The fix involves reducing the scope of the bridge lock to only the specific STP attributes that require it, allowing sleeping functions to be called safely outside the atomic section.
Affected products
- Linux Linux Kernel All versions prior to the fix in 2026
Timeline
- 2026-05-26: patched: Initial fix authored by Ido Schimmel
- 2026-07-19: disclosed: CVE-2026-63989 published