❌

Normal view

Received β€” 6 August 2026 ⏭ /r/netsec - Information Security News & Discussion

New Linux Bridge STP Vulnerability

A use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation.

A bridge that is administratively down while kernel STP is enabled, together with a port driven into the LEARNING state, arms periodic STP timers without an IFF_UP guard.

The teardown path taken by dellink never synchronously deletes those timers, so the backing net_device (which embeds struct net bridge as private data) is freed with a timer list still queued on a per-CPU timer base.

The result is a slab use-after-free in the kmalloc-cg-8k cache.

submitted by /u/SSDisclosure
[link] [comments]
❌