A newly disclosed Linux kernel vulnerability in the bridge subsystem's Spanning Tree Protocol (STP) implementation can trigger a use-after-free when STP timers are armed on an administratively down bridge and a port is forced into the LEARNING state without an IFF_UP guard. If the bridge device is then deleted, the teardown path can leave queued timers behind even after the backing net_device and embedded struct net_bridge memory have been freed, leading to memory corruption in the kmalloc-cg-8k slab cache.
A public proof-of-concept has now been released, increasing the risk of crashes and denial-of-service on affected systems and raising the possibility of further exploitation through controlled slab reallocation and potential control-flow hijacking. Researchers traced the bug to inconsistent cleanup between normal interface shutdown and direct bridge deletion in net/bridge, where the deletion path does not invoke the same STP timer cleanup routine; the issue was addressed in Linux kernel commit 2a00517db8de4be7df3d483b215c5544fb30a191, and systems running earlier kernels should be updated.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers released a public proof-of-concept demonstrating the Linux kernel bridge STP use-after-free bug and the affected object lifecycle. Reporting said the issue could cause crashes or denial of service and might potentially be developed into a control-flow hijacking primitive through controlled slab reallocation.
A patch for the bridge STP use-after-free vulnerability was introduced in Linux kernel commit 2a00517db8de4be7df3d483b215c5544fb30a191. The fix addresses the inconsistent cleanup path that could leave STP timers active after bridge deletion.
A new Linux kernel vulnerability was disclosed in the bridge subsystem's Spanning Tree Protocol implementation. The flaw is a use-after-free condition triggered when STP timers remain armed after a bridge device is deleted under specific down-state and LEARNING-state conditions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.