Use-after-free in Linux kernel - CVE-2026-72389
Published: August 15, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the STP timer handling in the Linux kernel bridge subsystem when deleting a bridge while the topology change timer is armed on an administratively down bridge. A local user can trigger bridge topology change detection and delete the bridge to cause a denial of service.
The issue occurs because the IFF_UP check was missing in br_topology_change_detection().
Affected software
openEuler
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-headers
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
python3-perf-debuginfo
How to mitigate CVE-2026-72389
kernel - update to 6.6.0-145.1.24.161
bpftool - update to 6.6.0-145.1.24.161
bpftool-debuginfo - update to 6.6.0-145.1.24.161
kernel-debuginfo - update to 6.6.0-145.1.24.161
kernel-debugsource - update to 6.6.0-145.1.24.161
kernel-devel - update to 6.6.0-145.1.24.161
kernel-headers - update to 6.6.0-145.1.24.161
kernel-source - update to 6.6.0-145.1.24.161
kernel-tools - update to 6.6.0-145.1.24.161
kernel-tools-debuginfo - update to 6.6.0-145.1.24.161
kernel-tools-devel - update to 6.6.0-145.1.24.161
perf - update to 6.6.0-145.1.24.161
perf-debuginfo - update to 6.6.0-145.1.24.161
python3-perf - update to 6.6.0-145.1.24.161
python3-perf-debuginfo - update to 6.6.0-145.1.24.161
External References
- https://git.kernel.org/stable/c/297a747f59bff6573196d7236178144d66524e68
- https://git.kernel.org/stable/c/2a00517db8de4be7df3d483b215c5544fb30a191
- https://git.kernel.org/stable/c/39283907a25e5caf0f2bd2947f6e56644b01e2b7
- https://git.kernel.org/stable/c/40cbfa3a28e0919469d1b086629bb3ce38a83593
- https://git.kernel.org/stable/c/4c40eec06eeac37c58e47a6058eb32901218d5d4
- https://git.kernel.org/stable/c/b4b3458ef88df4798632619f018791d4344bcd92
- https://git.kernel.org/stable/c/c86579b0a2d201792bcb59316629f4ba4758cfc8