Junglewise Threat Intelligence

CVE-2026-72389: Linux kernel bridge STP use-after-free when deleting a bridge

CVE-2026-72389 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's bridge Spanning Tree Protocol (STP) implementation contains a use-after-free vulnerability that can occur when a bridge device is deleted. An attacker with local access can trigger a topology change detection on a bridge that is administratively down, causing a timer to fire after the bridge is deleted and leading to a kernel crash or potential code execution.

Technical details

The vulnerability is a use-after-free in the kernel's net/bridge/br_stp.c module. The root cause is a missing IFF_UP flag check in the br_topology_change_detection() function, which allows STP timers to be armed while the bridge interface is administratively down. When the bridge is deleted, these armed timers are not properly shut down, causing them to reference freed memory. The fix adds the missing IFF_UP check before arming the topology change timer and synchronously shuts down all three STP timers during bridge deletion. This is a local vulnerability requiring bridge interface manipulation capabilities.

Affected products

  • Linux Linux kernel All versions since 2.6.12-rc2

Timeline

  • 2026-08-15: disclosed: CVE-2026-72389 published
  • 2026-06-29: patched: Upstream fix committed (commit 2a00517db8de4be7df3d483b215c5544fb30a191)
  • 2026-07-24: patched: Backported to stable tree

References

Related threats