CVE-2026-64032
Last modified
CVE-2026-64032 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix a possible use-after-free when removing a bridge port When per-VLAN multicast snooping is enabled, the bridge iterates over all the bridge ports, disables the per-port multicast context on each port and enables the per-{port, VLAN} multicast contexts instead. The reverse happens when per-VLAN multicast snooping is disabled. When global multicast snooping is enabled, the bridge iterates over all the bridge ports and enables the per-port multicast context on each port. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix a possible use-after-free when removing a bridge port When per-VLAN multicast snooping is enabled, the bridge iterates over all the bridge ports, disables the per-port multicast context on each port and enables the per-{port, VLAN} multicast contexts instead. The reverse happens when per-VLAN multicast snooping is disabled. When global multicast snooping is enabled, the bridge iterates over all the bridge ports and enables the per-port multicast context on each port. The reverse happens when multicast snooping is disabled. The above scheme can result in a situation where both types of contexts (per-port and per-{port, VLAN}) are enabled on a single bridge port: # ip link add name br1 up type bridge mcast_snooping 1 mcast_querier 1 vlan_filtering 1 # ip link add name dummy1 up master br1 type dummy # ip link set dev br1 type bridge mcast_vlan_snooping 1 # ip link set dev br1 type bridge mcast_snooping 0 # ip link set dev br1 type bridge mcast_snooping 1 This is not intended and it is a problem since the commit cited below. Prior to this commit, when removing a bridge port, br_multicast_disable_port() would disable the per-port multicast context and the per-{port, VLAN} multicast contexts would get disabled when flushing VLANs. After this commit, br_multicast_disable_port() only disables the per-port multicast context if per-VLAN multicast snooping is disabled. If both types of contexts were enabled on the port when it was removed, the per-port multicast context would remain enabled when freeing the bridge port, leading to a use-after-free [1]. Fix by preventing the bridge from enabling / disabling the per-port multicast contexts when toggling global multicast snooping if per-VLAN multicast snooping is enabled. [1] ODEBUG: free active (active state 0) object: ffff88810f8bda78 object type: timer_list hint: br_ip6_multicast_port_query_expired (net/bridge/br_multicast.c:1927) WARNING: lib/debugobjects.c:629 at debug_print_object+0x1b1/0x3e0, CPU#5: swapper/5/0 [...] Call Trace: <IRQ> __debug_check_no_obj_freed (lib/debugobjects.c:1116) kfree (mm/slub.c:2620 mm/slub.c:6250 mm/slub.c:6565) kobject_cleanup (lib/kobject.c:689) rcu_do_batch (kernel/rcu/tree.c:2617) rcu_core (kernel/rcu/tree.c:2869) handle_softirqs (kernel/softirq.c:622) __irq_exit_rcu (kernel/softirq.c:656 kernel/softirq.c:496 kernel/softirq.c:735) irq_exit_rcu (kernel/softirq.c:752) sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1061 (discriminator 47) arch/x86/kernel/apic/apic.c:1061 (discriminator 47)) </IRQ>
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 410a033bfa8c7daefbae0225c836693db2149ec1, < ddefd1b8e5eb58933a697ab38334f0fd82e7fb8b; >= c6d16eab122744df698f18b47cf771945cd55066, < ed3b69e60385a03df11c6d12e5d7bdf0f4a11b70; >= b4c83b37490d61cfdd62a2b29e98a9b89004b5c0, < 1900ca8acb92fbea8bf9abef9927c7fed03db7fc; >= 78f768e36c065ca3f88272fcf39014782c2d4ecd, < ebe5561154c823b323bd06e350b55e0b8604d851; >= 4b30ae9adb047dd0a7982975ec3933c529537026, < a9224862d597d0eed0a34bbb27343f703fc4113f; >= 4b30ae9adb047dd0a7982975ec3933c529537026, < 7213256c91ed778a0997c2029c152b18dc50e4fd; >= 4b30ae9adb047dd0a7982975ec3933c529537026, < 4df78ff02629c7729168f0696a7a2123c389818d; c996e25df0b3282c724bb5aca434518bc08cd963; >= 5.15.186, < 5.15.209; >= 6.1.142, < 6.1.175; >= 6.6.95, < 6.6.142; >= 6.12.35, < 6.12.92; >= 6.15.4, < 6.16 |
| Linux | Linux | 6.16 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-64032?
How severe is CVE-2026-64032?
How do I fix CVE-2026-64032?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-64027In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64028In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64029In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-6403The Quick Playground plugin for WordPress is vulnerable to P…7.5
- CVE-2026-64030In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-64031In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64033In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64034In the Linux kernel, the following vulnerability has been re…9.3
- CVE-2026-64035In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64036In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64037In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64038In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-64032?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
