SB20260905111 - Use-after-free in Linux kernel bridge
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-80842)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the Linux bridge multicast handling for master VLANs when processing IGMP traffic during master VLAN teardown. A remote attacker can send IGMP traffic to the bridge device while a master VLAN is being removed to cause memory corruption.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/22226a2c3b90f15b0925f1464470d3baa6c5677e
- https://git.kernel.org/stable/c/3a0ad4fcdfa0b7dba1876de14a12cb65c8b5ca50
- https://git.kernel.org/stable/c/3afaaee2f972aec9059110953adb62fa3cf5c4bd
- https://git.kernel.org/stable/c/3f4752996735e0628af559aa8da1d872c2fac13b
- https://git.kernel.org/stable/c/50e5c6605cc9c2dd57bd2d1b3459674d19738983
- https://git.kernel.org/stable/c/57f94d3f4dee8b54d63cefddf1112be4656ef9e6
- https://git.kernel.org/stable/c/7c54fd8cfbcf371a5ef50db5c53fe6e85fb76686
- https://git.kernel.org/stable/c/c069f29da72324697aa4b7cab5b3647a7d24a575