CVE-2026-46086

NONE EPSS 2.4%
Published May 27, 20261mo ago · Modified Jun 19, 20261w ago
Find Similar
Published May 27, 2026 1mo ago
Last Modified Jun 19, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: net: bridge: use a stable FDB dst snapshot in RCU readers Local FDB entries can be rewritten in place by `fdb_delete_local()`, which updates `f->dst` to another port or to `NULL` while keeping the entry alive. Several bridge RCU readers inspect `f->dst`, including `br_fdb_fillbuf()` through the `brforward_read()` sysfs path. These readers currently load `f->dst` multiple times and can therefore observe inconsistent values across the check and later dereference. In `br_fdb_fillbuf()`, this means a concurrent local-FDB update can change `f->dst` after the NULL check and before the `port_no` dereference, leading to a NULL-ptr-deref. Fix this by taking a single `READ_ONCE()` snapshot of `f->dst` in each affected RCU reader and using that snapshot for the rest of the access sequence. Also publish the in-place `f->dst` updates in `fdb_delete_local()` with `WRITE_ONCE()` so the readers and writer use matching access patterns.

Threat Intelligence

EPSS Exploit Probability
2.4% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

References 8

  • git.kernel.org https://git.kernel.org/stable/c/0b9e4bbfb7c949151e3acd44ed4aa33614d2e110
  • git.kernel.org https://git.kernel.org/stable/c/1406c4e0ed1eaf8a29801ab1163d00fb7ee4359a
  • git.kernel.org https://git.kernel.org/stable/c/5424e678f9b304e148cf5dcc047cffc7a56a3bb5
  • git.kernel.org https://git.kernel.org/stable/c/81af4137a30c4c2dc694dea8cacb180bd66000ef
  • git.kernel.org https://git.kernel.org/stable/c/9a2d9d4e657b23dc21f24cf139e3aeff0b61341f
  • git.kernel.org https://git.kernel.org/stable/c/a6ae4511c07b91f597e461406c6330f0d4ff810e
  • git.kernel.org https://git.kernel.org/stable/c/c502fa9f094cb03d1d1685c71e2105ab359bc2b8
  • git.kernel.org https://git.kernel.org/stable/c/df4601653201de21b487c3e7fffd464790cab808

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.