Executive brief
A vulnerability in the Linux kernel's network bridging component could allow a local user to cause a system crash. The issue occurs when specific multicast network settings are enabled and disabled in a particular order, leading to a memory error when a network port is removed. This primarily impacts system availability and stability.
Technical details
A use-after-free vulnerability exists in the Linux kernel bridge multicast implementation (net/bridge/br_multicast.c). The flaw is triggered when both per-port and per-VLAN multicast contexts are inadvertently enabled on a single bridge port due to a specific sequence of toggling 'mcast_snooping' and 'mcast_vlan_snooping'. When the port is subsequently removed, 'br_multicast_disable_port()' may fail to disable the per-port context if per-VLAN snooping is active, leaving active timers (like 'br_ip6_multicast_port_query_expired') associated with memory that is then freed. An attacker with local administrative privileges to configure network interfaces could exploit this to cause a kernel panic. The fix ensures that per-port multicast contexts are not improperly enabled or disabled when global snooping is toggled if VLAN-aware snooping is already active.
Affected products
- Linux Foundation Linux kernel versions prior to the fix in 2026
Timeline
- 2026-05-17: disclosed: Initial patch submission by Ido Schimmel
- 2026-06-01: patched: Patch committed to stable tree by Greg Kroah-Hartman
- 2026-07-19: advisory: CVE-2026-64032 published
References
- https://git.kernel.org/stable/c/1900ca8acb92fbea8bf9abef9927c7fed03db7fc
- https://git.kernel.org/stable/c/4df78ff02629c7729168f0696a7a2123c389818d
- https://git.kernel.org/stable/c/7213256c91ed778a0997c2029c152b18dc50e4fd
- https://git.kernel.org/stable/c/a9224862d597d0eed0a34bbb27343f703fc4113f
- https://git.kernel.org/stable/c/ddefd1b8e5eb58933a697ab38334f0fd82e7fb8b
- https://git.kernel.org/stable/c/ebe5561154c823b323bd06e350b55e0b8604d851
- https://git.kernel.org/stable/c/ed3b69e60385a03df11c6d12e5d7bdf0f4a11b70