Junglewise Threat Intelligence

CVE-2026-64032: Linux kernel use-after-free in bridge multicast port removal

CVE-2026-64032 · Severity: info · CVSS 5.5 · Published 2026-07-19

Vendors: Linux Foundation.

Executive brief

A vulnerability in the Linux kernel's network bridging component could allow a local user to cause a system crash. The issue occurs when specific multicast network settings are enabled and disabled in a particular order, leading to a memory error when a network port is removed. This primarily impacts system availability and stability.

Technical details

A use-after-free vulnerability exists in the Linux kernel bridge multicast implementation (net/bridge/br_multicast.c). The flaw is triggered when both per-port and per-VLAN multicast contexts are inadvertently enabled on a single bridge port due to a specific sequence of toggling 'mcast_snooping' and 'mcast_vlan_snooping'. When the port is subsequently removed, 'br_multicast_disable_port()' may fail to disable the per-port context if per-VLAN snooping is active, leaving active timers (like 'br_ip6_multicast_port_query_expired') associated with memory that is then freed. An attacker with local administrative privileges to configure network interfaces could exploit this to cause a kernel panic. The fix ensures that per-port multicast contexts are not improperly enabled or disabled when global snooping is toggled if VLAN-aware snooping is already active.

Affected products

  • Linux Foundation Linux kernel versions prior to the fix in 2026

Timeline

  • 2026-05-17: disclosed: Initial patch submission by Ido Schimmel
  • 2026-06-01: patched: Patch committed to stable tree by Greg Kroah-Hartman
  • 2026-07-19: advisory: CVE-2026-64032 published

References