Junglewise Threat Intelligence

CVE-2026-63989: Linux Kernel bridge sleep in atomic context in netlink path

CVE-2026-63989 · Severity: info · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's network bridge component, which manages how different network segments communicate. Under certain conditions, the system could attempt to perform a 'sleep' operation while holding a lock that requires immediate, uninterrupted execution. This mismatch can lead to system instability or crashes (kernel panics), potentially causing a denial of service for the affected server.

Technical details

The vulnerability arises in the br_setport() function within the bridge netlink configuration path. Historically, br_setport() was called while holding the bridge spinlock (an atomic context). However, modern iterations of this function call dev_set_promiscuity(), which is a sleeping function. When certain bridge port flags are changed via netlink, the kernel attempts to sleep while holding the spinlock, triggering a 'scheduling while atomic' bug. This can result in a kernel splat or panic. The fix involves reducing the scope of the bridge lock to only the specific STP attributes that require it, allowing sleeping functions to be called safely outside the atomic section.

Affected products

  • Linux Linux Kernel All versions prior to the fix in 2026

Timeline

  • 2026-05-26: patched: Initial fix authored by Ido Schimmel
  • 2026-07-19: disclosed: CVE-2026-63989 published

References

Related threats