PT-2026-91329 · Azure Linux · Kernel

Publicado

2026-09-04

·

Atualizado

2026-09-04

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
br multicast toggle one vlan() clears BR VLFLAG MCAST ENABLED under br->multicast lock before stopping a VLAN's multicast context. That is the teardown handshake: lockless readers gate on the flag through br multicast ctx should use() -> br multicast ctx vlan disabled(), so once it is cleared under the lock no reader can arm the context again.
For a master VLAN the handshake never runs. vlan del() clears BRIDGE VLAN INFO BRENTRY before calling br vlan put master(), so br multicast toggle one vlan(masterv, false) returns early on !br vlan is brentry(vlan): the flag stays set and br->multicast lock is never taken. br vlan put master() then drains the context in br multicast ctx deinit() and frees the VLAN through call rcu(), while a reader still inside rcu read lock() sees the context as enabled and re-arms it. The port and port-VLAN branch of the function has no br vlan is brentry() test and flips the flag under br->multicast lock, so it is not affected.
The reader is the bridge transmit path. For a master VLAN br multicast rcv() selects brmctx = &vlan->br mcast ctx with pmctx = NULL, so IGMP sent to the bridge device re-arms the context's timers after br multicast ctx deinit() has already stopped them.
BUG: KASAN: slab-use-after-free in detach if pending+0x412/0x4a0 Write of size 8 at addr ffff88810ac39918 by task brmc/601 mod timer+0x51a/0xc50 br multicast host join+0x25b/0x390 br multicast add group+0x468/0x530 br ip4 multicast add group+0x1a0/0x260 br multicast rcv+0x2cda/0x61e0 br dev xmit+0x6c4/0x1540 Allocated by task 610: br vlan add+0x111/0xb40 br vlan info+0x370/0x3e0 Freed by task 0: kfree+0x1a7/0x4f0 rcu core+0x7dc/0x10a0
Only test br vlan is brentry() when enabling, like the br multicast ctx vlan global disabled() test next to it. Disabling then always clears BR VLFLAG MCAST ENABLED under br->multicast lock before br multicast ctx deinit() drains the context.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

AZL-99528

Produtos afetados

Kernel