In the Linux kernel, the following vulnerability has been resolved:
bridge: guard local VLAN-0 FDB helpers against NULL vlan group
When CONFIGBRIDGEVLANFILTERING is not set, brvlangroup() and nbpvlangroup() return NULL (brprivate.h stub definitions). The BRBOOLOPTFDBLOCALVLAN0 toggle code is compiled unconditionally and reaches brfdbdeletelocalspervlanport() and brfdbinsertlocalspervlanport(), where the NULL vlan group pointer is dereferenced via listforeachentry(v, &vg->vlan_list, vlist).
The observed crash is in the delete path, triggered when creating a bridge with IFLABRMULTIBOOLOPT containing BRBOOLOPTFDBLOCALVLAN0 via RTM_NEWLINK. The insert helper has the same bug pattern.
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000056: 0000 [#1] KASAN NOPTI KASAN: null-ptr-deref in range [0x00000000000002b0-0x00000000000002b7] RIP: 0010:brfdbdeletelocalspervlan+0x2b9/0x310 Call Trace: brfdbtogglelocalvlan0+0x452/0x4c0 brtogglefdblocalvlan0+0x31/0x80 net/bridge/br.c:276 brboolopttoggle net/bridge/br.c:313 brbooloptmultitoggle net/bridge/br.c:364 brchangelink net/bridge/brnetlink.c:1542 brdevnewlink net/bridge/br_netlink.c:1575
Add NULL checks for the vlan group pointer in both helpers, returning early when there are no VLANs to iterate. This matches the existing pattern used by other bridge FDB functions such as brfdbadd() and brfdbdelete().
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43100.json",
"cna_assigner": "Linux"
}