SB20260815332 - Use-after-free in Linux kernel bridge
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-72389)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the STP timer handling in the Linux kernel bridge subsystem when deleting a bridge while the topology change timer is armed on an administratively down bridge. A local user can trigger bridge topology change detection and delete the bridge to cause a denial of service.
The issue occurs because the IFF_UP check was missing in br_topology_change_detection().
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/297a747f59bff6573196d7236178144d66524e68
- https://git.kernel.org/stable/c/2a00517db8de4be7df3d483b215c5544fb30a191
- https://git.kernel.org/stable/c/39283907a25e5caf0f2bd2947f6e56644b01e2b7
- https://git.kernel.org/stable/c/40cbfa3a28e0919469d1b086629bb3ce38a83593
- https://git.kernel.org/stable/c/4c40eec06eeac37c58e47a6058eb32901218d5d4
- https://git.kernel.org/stable/c/b4b3458ef88df4798632619f018791d4344bcd92
- https://git.kernel.org/stable/c/c86579b0a2d201792bcb59316629f4ba4758cfc8