In the Linux kernel, the following vulnerability has been resolved:
bridge: mcast: Fix a possible use-after-free when removing a bridge port
When per-VLAN multicast snooping is enabled, the bridge iterates over all the bridge ports, disables the per-port multicast context on each port and enables the per-{port, VLAN} multicast contexts instead. The reverse happens when per-VLAN multicast snooping is disabled.
When global multicast snooping is enabled, the bridge iterates over all the bridge ports and enables the per-port multicast context on each port. The reverse happens when multicast snooping is disabled.
The above scheme can result in a situation where both types of contexts (per-port and per-{port, VLAN}) are enabled on a single bridge port:
# ip link add name br1 up type bridge mcastsnooping 1 mcastquerier 1 vlanfiltering 1 # ip link add name dummy1 up master br1 type dummy # ip link set dev br1 type bridge mcastvlansnooping 1 # ip link set dev br1 type bridge mcastsnooping 0 # ip link set dev br1 type bridge mcast_snooping 1
This is not intended and it is a problem since the commit cited below. Prior to this commit, when removing a bridge port, brmulticastdisable_port() would disable the per-port multicast context and the per-{port, VLAN} multicast contexts would get disabled when flushing VLANs.
After this commit, brmulticastdisable_port() only disables the per-port multicast context if per-VLAN multicast snooping is disabled. If both types of contexts were enabled on the port when it was removed, the per-port multicast context would remain enabled when freeing the bridge port, leading to a use-after-free [1].
Fix by preventing the bridge from enabling / disabling the per-port multicast contexts when toggling global multicast snooping if per-VLAN multicast snooping is enabled.
[1] ODEBUG: free active (active state 0) object: ffff88810f8bda78 object type: timerlist hint: brip6multicastportqueryexpired (net/bridge/brmulticast.c:1927) WARNING: lib/debugobjects.c:629 at debugprint_object+0x1b1/0x3e0, CPU#5: swapper/5/0 [...] Call Trace: <IRQ> __debugchecknoobjfreed (lib/debugobjects.c:1116) kfree (mm/slub.c:2620 mm/slub.c:6250 mm/slub.c:6565) kobjectcleanup (lib/kobject.c:689) rcudobatch (kernel/rcu/tree.c:2617) rcucore (kernel/rcu/tree.c:2869) handle_softirqs (kernel/softirq.c:622) _irqexitrcu (kernel/softirq.c:656 kernel/softirq.c:496 kernel/softirq.c:735) irqexitrcu (kernel/softirq.c:752) sysvecapictimerinterrupt (arch/x86/kernel/apic/apic.c:1061 (discriminator 47) arch/x86/kernel/apic/apic.c:1061 (discriminator 47)) </IRQ>
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64032.json",
"cna_assigner": "Linux"
}