A flaw tracked as CVE-2026-46086 in the Linux kernel's bridge networking component can let a low-privileged local attacker crash a system by triggering a race in forwarding database (FDB) handling. The bug stems from RCU readers loading the FDB destination pointer multiple times while concurrent updates can rewrite that pointer in place, allowing br_fdb_fillbuf() to pass a NULL check and later dereference a NULL pointer. Red Hat rated the issue Moderate with a CVSS v3.1 score of 5.5, classifying it as a CWE-367 time-of-check time-of-use race condition with denial-of-service impact only.
Upstream kernel maintainers fixed the issue by taking a stable snapshot of f->dst with READ_ONCE() in affected RCU readers and using WRITE_ONCE() for in-place updates in fdb_delete_local(). The vulnerability was introduced in kernel 3.14 and patched in stable releases including 6.6.140, 6.12.86, 6.18.27, 7.0.4, and 7.1-rc1. Red Hat said fixes are available for RHEL 8 kernel and kernel-rt, RHEL 9 kernel, and RHEL 10 kernel, while RHEL 7 kernel, **RHEL 7 kernel-rt`, and RHEL 9 kernel-rt remain affected; RHEL 6 is out of support and should be assumed vulnerable.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2026:47017 on 2026-07-28 to fix CVE-2026-46086 in the Red Hat Enterprise Linux 10 kernel.
On 2026-07-14, Red Hat issued RHSA-2026:39179 for the RHEL 8 kernel and RHSA-2026:39180 for the RHEL 8 kernel-rt to address CVE-2026-46086.
Red Hat's CVE entry for CVE-2026-46086 was last modified on 2026-07-13, reflecting updated status information for affected and fixed products.
Red Hat issued RHSA-2026:38491 on 2026-07-13 to fix CVE-2026-46086 in the Red Hat Enterprise Linux 9 kernel.
Red Hat published its advisory entry for CVE-2026-46086 on 2026-05-27, classifying the Linux kernel flaw as Moderate severity with denial-of-service impact.
On 2026-05-27, the Linux kernel CVE team publicly described CVE-2026-46086 as a bridge subsystem race condition that can cause a NULL-pointer dereference, and outlined the READ_ONCE/WRITE_ONCE-based fix approach.
The vulnerability tracked as CVE-2026-46086 was introduced in Linux kernel 3.14 by commit 960b589f86c74ce582922fcb996103271081f4de, affecting bridge networking code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.