PT-2026-91329 · Azure Linux · Kernel
Published
2026-09-04
·
Updated
2026-09-04
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
br multicast toggle one vlan() clears BR VLFLAG MCAST ENABLED under
br->multicast lock before stopping a VLAN's multicast context. That is
the teardown handshake: lockless readers gate on the flag through
br multicast ctx should use() -> br multicast ctx vlan disabled(), so
once it is cleared under the lock no reader can arm the context again.
For a master VLAN the handshake never runs. vlan del() clears
BRIDGE VLAN INFO BRENTRY before calling br vlan put master(), so
br multicast toggle one vlan(masterv, false) returns early on
!br vlan is brentry(vlan): the flag stays set and br->multicast lock is
never taken. br vlan put master() then drains the context in
br multicast ctx deinit() and frees the VLAN through call rcu(), while a
reader still inside rcu read lock() sees the context as enabled and
re-arms it. The port and port-VLAN branch of the function has no
br vlan is brentry() test and flips the flag under br->multicast lock,
so it is not affected.
The reader is the bridge transmit path. For a master VLAN
br multicast rcv() selects brmctx = &vlan->br mcast ctx with
pmctx = NULL, so IGMP sent to the bridge device re-arms the context's
timers after br multicast ctx deinit() has already stopped them.
BUG: KASAN: slab-use-after-free in detach if pending+0x412/0x4a0
Write of size 8 at addr ffff88810ac39918 by task brmc/601
mod timer+0x51a/0xc50
br multicast host join+0x25b/0x390
br multicast add group+0x468/0x530
br ip4 multicast add group+0x1a0/0x260
br multicast rcv+0x2cda/0x61e0
br dev xmit+0x6c4/0x1540
Allocated by task 610:
br vlan add+0x111/0xb40
br vlan info+0x370/0x3e0
Freed by task 0:
kfree+0x1a7/0x4f0
rcu core+0x7dc/0x10a0
Only test br vlan is brentry() when enabling, like the
br multicast ctx vlan global disabled() test next to it. Disabling then
always clears BR VLFLAG MCAST ENABLED under br->multicast lock before
br multicast ctx deinit() drains the context.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel