CVE-2026-74480

Source
https://cve.org/CVERecord?id=CVE-2026-74480
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74480.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74480
Downstream
Published
2026-08-15T12:27:13.803Z
Modified
2026-08-20T03:55:14.780668225Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net: bridge: stop fast-leave after deleting a port group
Details

In the Linux kernel, the following vulnerability has been resolved:

net: bridge: stop fast-leave after deleting a port group

brmulticastleavegroup() iterates mp->ports with pp = &p->next in its fast-leave path. After brmulticastdelpg() removes p, continuing the loop advances pp through the deleted entry.

If multicast-to-unicast was enabled, the bridge can hold multiple port groups for the same port and group with different source MAC addresses. Once multicast-to-unicast is disabled, brportgroup_equal() matches those entries by port only. A fast leave can then delete one entry and continue from its stale next pointer, leaving mp->ports pointing at a deleted port group.

Fast leave only needs to remove one matching port group. Break after brmulticastdel_pg() so the loop stops before dereferencing the removed entry.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74480.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6db6f0eae6052b70885562e1733896647ec1d807
Fixed
d6c32e2e25a9a06ba021030e26b6d602a277eb72
Fixed
482bcb85139addb4e8ac8ed10baeda3e0aad4031
Fixed
1a109cc9890d017c41d77e6c82da739579c49f0b
Fixed
159ad90cb929c033308bb39a2c5f8fbf393b77aa
Fixed
4695430e8132420bf8de94da3eb36a6cf35fde6b
Fixed
0309ebbc570000ea0df11c06b69798e5860c5f6f
Fixed
4c57056ca6aace2e9f94ae9298bf49ef6b0c95e4
Fixed
a39789f211b8a4125f0c70e05b30cf715f4f187d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74480.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.11.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74480.json"