In the Linux kernel, the following vulnerability has been resolved:
net: bridge: mst: fix suspicious rcu usage in brmstset_state
I converted brmstset_state to RCU to avoid a vlan use-after-free but forgot to change the vlan group dereference helper. Switch to vlan group RCU deref helper to fix the suspicious rcu usage warning.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/40xxx/CVE-2024-40920.json"
}[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"104355912225764579961368957962623983187",
"71836307035913514805402792644270200065",
"333021288262385202592527230440429008858",
"163461609863869161264060498088574133559"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@546ceb1dfdac866648ec959cbc71d9525bd73462",
"deprecated": false,
"id": "CVE-2024-40920-0a363ea1",
"signature_type": "Line",
"target": {
"file": "net/bridge/br_mst.c"
},
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"104355912225764579961368957962623983187",
"71836307035913514805402792644270200065",
"333021288262385202592527230440429008858",
"163461609863869161264060498088574133559"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7caefa2771722e65496d85b62e1dc4442b7d1345",
"deprecated": false,
"id": "CVE-2024-40920-1f4f5475",
"signature_type": "Line",
"target": {
"file": "net/bridge/br_mst.c"
},
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"104355912225764579961368957962623983187",
"71836307035913514805402792644270200065",
"333021288262385202592527230440429008858",
"163461609863869161264060498088574133559"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@caaa2129784a04dcade0ea92c12e6ff90bbd23d8",
"deprecated": false,
"id": "CVE-2024-40920-3859bc97",
"signature_type": "Line",
"target": {
"file": "net/bridge/br_mst.c"
},
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"104355912225764579961368957962623983187",
"71836307035913514805402792644270200065",
"333021288262385202592527230440429008858",
"163461609863869161264060498088574133559"
]
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@406bfc04b01ee47e4c626f77ecc7d9f85135b166",
"deprecated": false,
"id": "CVE-2024-40920-f3368718",
"signature_type": "Line",
"target": {
"file": "net/bridge/br_mst.c"
},
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-40920.json"