Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99528.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-99528
Upstream
Published
2026-09-04T16:18:12Z
Modified
2026-09-05T14:17:03.893831944Z
Summary
CVE-2026-80842 affecting package kernel 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

net: bridge: mcast: fix use-after-free of a master VLAN's multicast context

brmulticasttoggleonevlan() clears BRVLFLAGMCASTENABLED under br->multicastlock before stopping a VLAN's multicast context. That is the teardown handshake: lockless readers gate on the flag through brmulticastctxshoulduse() -> brmulticastctxvlandisabled(), so once it is cleared under the lock no reader can arm the context again.

For a master VLAN the handshake never runs. __vlandel() clears BRIDGEVLANINFOBRENTRY before calling brvlanputmaster(), so brmulticasttoggleonevlan(masterv, false) returns early on !brvlanisbrentry(vlan): the flag stays set and br->multicastlock is never taken. brvlanputmaster() then drains the context in brmulticastctxdeinit() and frees the VLAN through callrcu(), while a reader still inside rcureadlock() sees the context as enabled and re-arms it. The port and port-VLAN branch of the function has no brvlanisbrentry() test and flips the flag under br->multicastlock, so it is not affected.

The reader is the bridge transmit path. For a master VLAN brmulticastrcv() selects brmctx = &vlan->brmcastctx with pmctx = NULL, so IGMP sent to the bridge device re-arms the context's timers after brmulticastctx_deinit() has already stopped them.

BUG: KASAN: slab-use-after-free in detachifpending+0x412/0x4a0 Write of size 8 at addr ffff88810ac39918 by task brmc/601 __modtimer+0x51a/0xc50 brmulticasthostjoin+0x25b/0x390 __brmulticastaddgroup+0x468/0x530 brip4multicastaddgroup+0x1a0/0x260 brmulticastrcv+0x2cda/0x61e0 brdevxmit+0x6c4/0x1540 Allocated by task 610: brvlanadd+0x111/0xb40 brvlaninfo+0x370/0x3e0 Freed by task 0: kfree+0x1a7/0x4f0 rcucore+0x7dc/0x10a0

Only test brvlanisbrentry() when enabling, like the brmulticastctxvlanglobaldisabled() test next to it. Disabling then always clears BRVLFLAGMCASTENABLED under br->multicastlock before brmulticastctx_deinit() drains the context.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99528.json"