In the Linux kernel, the following vulnerability has been resolved: net: bridge: mcast: wait for previous gc cycles when removing port syzbot hit a use-after-free[1] which is caused because the bri…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: net: bridge: mcast: wait for previous gc cycles when removing port syzbot hit a use-after-free[1] which is caused because the bridge doesn't make sure that all previous garbage has been collected when removing a port. What happens is: CPU 1 CPU 2 start gc cycle remove port acquire gc lock first wait for lock call br_multicasg_gc() directly …
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/0d8b26e10e680c01522d7cc14abe04c3265a928f Patch
- https://git.kernel.org/stable/c/1e16828020c674b3be85f52685e8b80f9008f50f Patch
- https://git.kernel.org/stable/c/92c4ee25208d0f35dafc3213cdf355fbe449e078 Patch
- https://git.kernel.org/stable/c/b2f794b168cf560682ff976b255aa6d29d14a658 Patch
- https://git.kernel.org/stable/c/e3145ca904fa8dbfd1a5bf0187905bc117b0efce Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
Timeline
- nvd_ingest NVD