{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64032","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.028Z","datePublished":"2026-07-19T15:39:22.228Z","dateUpdated":"2026-08-05T12:38:26.376Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:38:26.376Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: mcast: Fix a possible use-after-free when removing a bridge port\n\nWhen per-VLAN multicast snooping is enabled, the bridge iterates over\nall the bridge ports, disables the per-port multicast context on each\nport and enables the per-{port, VLAN} multicast contexts instead. The\nreverse happens when per-VLAN multicast snooping is disabled.\n\nWhen global multicast snooping is enabled, the bridge iterates over all\nthe bridge ports and enables the per-port multicast context on each\nport. The reverse happens when multicast snooping is disabled.\n\nThe above scheme can result in a situation where both types of contexts\n(per-port and per-{port, VLAN}) are enabled on a single bridge port:\n\n # ip link add name br1 up type bridge mcast_snooping 1 mcast_querier 1 vlan_filtering 1\n # ip link add name dummy1 up master br1 type dummy\n # ip link set dev br1 type bridge mcast_vlan_snooping 1\n # ip link set dev br1 type bridge mcast_snooping 0\n # ip link set dev br1 type bridge mcast_snooping 1\n\nThis is not intended and it is a problem since the commit cited below.\nPrior to this commit, when removing a bridge port,\nbr_multicast_disable_port() would disable the per-port multicast context\nand the per-{port, VLAN} multicast contexts would get disabled when\nflushing VLANs.\n\nAfter this commit, br_multicast_disable_port() only disables the\nper-port multicast context if per-VLAN multicast snooping is disabled.\nIf both types of contexts were enabled on the port when it was removed,\nthe per-port multicast context would remain enabled when freeing the\nbridge port, leading to a use-after-free [1].\n\nFix by preventing the bridge from enabling / disabling the per-port\nmulticast contexts when toggling global multicast snooping if per-VLAN\nmulticast snooping is enabled.\n\n[1]\nODEBUG: free active (active state 0) object: ffff88810f8bda78 object type: timer_list hint: br_ip6_multicast_port_query_expired (net/bridge/br_multicast.c:1927)\nWARNING: lib/debugobjects.c:629 at debug_print_object+0x1b1/0x3e0, CPU#5: swapper/5/0\n[...]\nCall Trace:\n<IRQ>\n__debug_check_no_obj_freed (lib/debugobjects.c:1116)\nkfree (mm/slub.c:2620 mm/slub.c:6250 mm/slub.c:6565)\nkobject_cleanup (lib/kobject.c:689)\nrcu_do_batch (kernel/rcu/tree.c:2617)\nrcu_core (kernel/rcu/tree.c:2869)\nhandle_softirqs (kernel/softirq.c:622)\n__irq_exit_rcu (kernel/softirq.c:656 kernel/softirq.c:496 kernel/softirq.c:735)\nirq_exit_rcu (kernel/softirq.c:752)\nsysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1061 (discriminator 47) arch/x86/kernel/apic/apic.c:1061 (discriminator 47))\n</IRQ>"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable code is reached only through local bridge administration (rtnetlink RTM_NEWLINK, bridge ioctl, or sysfs), not through processing of remote network packets. An attacker must issue `ip link`/`bridge` configuration commands to create the inconsistent multicast state and remove a bridge port.\nAC:L - The reproducer sequence is fully attacker-controlled and deterministic; syzkaller triggered it reliably. The attacker configures the toggle sequence, removes the port, and the orphaned IGMP/MLD query timers fire on schedule without depending on uncontrollable timing or memory layout.\nPR:L - All entry paths require CAP_NET_ADMIN in the target network namespace (rtnetlink at rtnl_newlink, br_ioctl add_del_if, sysfs bridge attributes). Unprivileged local users can obtain this capability by creating a user+network namespace (`unshare -Urn`), which is widely enabled on server and container hosts.\nUI:N - Exploitation requires no action from any other user or victim; the attacker performs the entire bridge setup, state toggling, and port removal themselves.\nS:U - Successful exploitation corrupts kernel memory within the same kernel security domain. This is a standard local kernel memory corruption issue, not a cross-boundary escape such as VM guest-to-host or IOMMU bypass.\nC:H - This is a heap use-after-free on a freed net_bridge_port structure; the timer callback dereferences pmctx->port->br on freed memory. UAF on kernel slab objects enables arbitrary kernel memory reads via heap grooming and reclamation of the freed port object.\nI:H - The UAF occurs in a timer softirq handler that reads and writes through fields of the freed port multicast context, including sending queries via br_multicast_send_query. Kernel heap UAF is exploitable for arbitrary write and control-flow hijack primitives, not merely a crash.\nA:H - The freed port structure is kfree'd while IGMP/MLD own-query timers remain active, producing a debugobjects \"free active timer\" warning and use-after-free in softirq. This reliably causes kernel oops/panic and can be triggered repeatedly to deny service on shared infrastructure such as cloud hosts or software switches."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bridge/br_multicast.c"],"versions":[{"version":"410a033bfa8c7daefbae0225c836693db2149ec1","lessThan":"ddefd1b8e5eb58933a697ab38334f0fd82e7fb8b","status":"affected","versionType":"git"},{"version":"c6d16eab122744df698f18b47cf771945cd55066","lessThan":"ed3b69e60385a03df11c6d12e5d7bdf0f4a11b70","status":"affected","versionType":"git"},{"version":"b4c83b37490d61cfdd62a2b29e98a9b89004b5c0","lessThan":"1900ca8acb92fbea8bf9abef9927c7fed03db7fc","status":"affected","versionType":"git"},{"version":"78f768e36c065ca3f88272fcf39014782c2d4ecd","lessThan":"ebe5561154c823b323bd06e350b55e0b8604d851","status":"affected","versionType":"git"},{"version":"4b30ae9adb047dd0a7982975ec3933c529537026","lessThan":"a9224862d597d0eed0a34bbb27343f703fc4113f","status":"affected","versionType":"git"},{"version":"4b30ae9adb047dd0a7982975ec3933c529537026","lessThan":"7213256c91ed778a0997c2029c152b18dc50e4fd","status":"affected","versionType":"git"},{"version":"4b30ae9adb047dd0a7982975ec3933c529537026","lessThan":"4df78ff02629c7729168f0696a7a2123c389818d","status":"affected","versionType":"git"},{"version":"c996e25df0b3282c724bb5aca434518bc08cd963","status":"affected","versionType":"git"},{"version":"5.15.186","lessThan":"5.15.209","status":"affected","versionType":"semver"},{"version":"6.1.142","lessThan":"6.1.175","status":"affected","versionType":"semver"},{"version":"6.6.95","lessThan":"6.6.142","status":"affected","versionType":"semver"},{"version":"6.12.35","lessThan":"6.12.92","status":"affected","versionType":"semver"},{"version":"6.15.4","lessThan":"6.16","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bridge/br_multicast.c"],"versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","status":"unaffected","versionType":"semver"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.186","versionEndExcluding":"5.15.209"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.142","versionEndExcluding":"6.1.175"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.95","versionEndExcluding":"6.6.142"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.35","versionEndExcluding":"6.12.92"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"6.18.34"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"7.0.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"7.1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15.4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ddefd1b8e5eb58933a697ab38334f0fd82e7fb8b"},{"url":"https://git.kernel.org/stable/c/ed3b69e60385a03df11c6d12e5d7bdf0f4a11b70"},{"url":"https://git.kernel.org/stable/c/1900ca8acb92fbea8bf9abef9927c7fed03db7fc"},{"url":"https://git.kernel.org/stable/c/ebe5561154c823b323bd06e350b55e0b8604d851"},{"url":"https://git.kernel.org/stable/c/a9224862d597d0eed0a34bbb27343f703fc4113f"},{"url":"https://git.kernel.org/stable/c/7213256c91ed778a0997c2029c152b18dc50e4fd"},{"url":"https://git.kernel.org/stable/c/4df78ff02629c7729168f0696a7a2123c389818d"}],"title":"bridge: mcast: Fix a possible use-after-free when removing a bridge port","x_generator":{"engine":"bippy-1.2.0"}}}}