Answer in brief
CVE-2026-64032 records a Unknown severity vulnerability in bridge: mcast: Fix a possible use-after-free when removing a bridge port. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64032 records a Unknown severity vulnerability in bridge: mcast: Fix a possible use-after-free when removing a bridge port. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=410a033bfa8c7daefbae0225c836693db2149ec1 <ddefd1b8e5eb58933a697ab38334f0fd82e7fb8b || >=c6d16eab122744df698f18b47cf771945cd55066 <ed3b69e60385a03df11c6d12e5d7bdf0f4a11b70 || >=b4c83b37490d61cfdd62a2b29e98a9b89004b5c0 <1900ca8acb92fbea8bf9abef9927c7fed03db7fc || >=78f768e36c065ca3f88272fcf39014782c2d4ecd <ebe5561154c823b323bd06e350b55e0b8604d851 || >=4b30ae9adb047dd0a7982975ec3933c529537026 <a9224862d597d0eed0a34bbb27343f703fc4113f || >=4b30ae9adb047dd0a7982975ec3933c529537026 <7213256c91ed778a0997c2029c152b18dc50e4fd || >=4b30ae9adb047dd0a7982975ec3933c529537026 <4df78ff02629c7729168f0696a7a2123c389818d || c996e25df0b3282c724bb5aca434518bc08cd963 || >=5.15.186 <5.15.209 || >=6.1.142 <6.1.175 || >=6.6.95 <6.6.142 || >=6.12.35 <6.12.92 || >=6.15.4 <6.16 | ddefd1b8e5eb58933a697ab38334f0fd82e7fb8b, ed3b69e60385a03df11c6d12e5d7bdf0f4a11b70, 1900ca8acb92fbea8bf9abef9927c7fed03db7fc, ebe5561154c823b323bd06e350b55e0b8604d851, a9224862d597d0eed0a34bbb27343f703fc4113f, 7213256c91ed778a0997c2029c152b18dc50e4fd, 4df78ff02629c7729168f0696a7a2123c389818d, 5.15.209, 6.1.175, 6.6.142, 6.12.92, 6.16 |
| Linux/Linuxgeneric | 6.16 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix a possible use-after-free when removing a bridge port When per-VLAN multicast snooping is enabled, the bridge iterates over all the bridge ports, disables the per-port multicast context on each port and enables the per-{port, VLAN} multicast contexts instead. The reverse happens when per-VLAN multicast snooping is disabled. When global multicast snooping is enabled, the bridge iterates over all the bridge ports and enables the per-port multicast context on each port. The reverse happens when multicast snooping is disabled. The above scheme can result in a situation where both types of contexts (per-port and per-{port, VLAN}) are enabled on a single bridge port: # ip link add name br1 up type bridge mcast_snooping 1 mcast_querier 1 vlan_filtering 1 # ip link add name dummy1 up master br1 type dummy # ip link set dev br1 type bridge mcast_vlan_snooping 1 # ip link set dev br1 type bridge mcast_snooping 0 # ip link set dev br1 type bridge mcast_snooping 1 This is not intended and it is a problem since the commit cited below. Prior to this commit, when removing a bridge port, br_multicast_disable_port() would disable the per-port multicast context and the per-{port, VLAN} multicast contexts would get disabled when flushing VLANs. After this commit, br_multicast_disable_port() only disables the per-port multicast context if per-VLAN multicast snooping is disabled. If both types of contexts were enabled on the port when it was removed, the per-port multicast context would remain enabled when freeing the bridge port, leading to a use-after-free [1]. Fix by preventing the bridge from enabling / disabling the per-port multicast contexts when toggling global multicast snooping if per-VLAN multicast snooping is enabled. [1] ODEBUG: free active (active state 0) object: ffff88810f8bda78 object type: timer_list hint: br_ip6_multicast_port_query_expired (net/bridge/br_multicast.c:1927) WARNING: lib/debugobjects.c:629 at debug_print_object+0x1b1/0x3e0, CPU#5: swapper/5/0 [...] Call Trace: <IRQ> __debug_check_no_obj_freed (lib/debugobjects.c:1116) kfree (mm/slub.c:2620 mm/slub.c:6250 mm/slub.c:6565) kobject_cleanup (lib/kobject.c:689) rcu_do_batch (kernel/rcu/tree.c:2617) rcu_core (kernel/rcu/tree.c:2869) handle_softirqs (kernel/softirq.c:622) __irq_exit_rcu (kernel/softirq.c:656 kernel/softirq.c:496 kernel/softirq.c:735) irq_exit_rcu (kernel/softirq.c:752) sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1061 (discriminator 47) arch/x86/kernel/apic/apic.c:1061 (discriminator 47)) </IRQ>
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=410a033bfa8c7daefbae0225c836693db2149ec1 <ddefd1b8e5eb58933a697ab38334f0fd82e7fb8b || >=c6d16eab122744df698f18b47cf771945cd55066 <ed3b69e60385a03df11c6d12e5d7bdf0f4a11b70 || >=b4c83b37490d61cfdd62a2b29e98a9b89004b5c0 <1900ca8acb92fbea8bf9abef9927c7fed03db7fc || >=78f768e36c065ca3f88272fcf39014782c2d4ecd <ebe5561154c823b323bd06e350b55e0b8604d851 || >=4b30ae9adb047dd0a7982975ec3933c529537026 <a9224862d597d0eed0a34bbb27343f703fc4113f || >=4b30ae9adb047dd0a7982975ec3933c529537026 <7213256c91ed778a0997c2029c152b18dc50e4fd || >=4b30ae9adb047dd0a7982975ec3933c529537026 <4df78ff02629c7729168f0696a7a2123c389818d || c996e25df0b3282c724bb5aca434518bc08cd963 || >=5.15.186 <5.15.209 || >=6.1.142 <6.1.175 || >=6.6.95 <6.6.142 || >=6.12.35 <6.12.92 || >=6.15.4 <6.16 | ddefd1b8e5eb58933a697ab38334f0fd82e7fb8b, ed3b69e60385a03df11c6d12e5d7bdf0f4a11b70, 1900ca8acb92fbea8bf9abef9927c7fed03db7fc, ebe5561154c823b323bd06e350b55e0b8604d851, a9224862d597d0eed0a34bbb27343f703fc4113f, 7213256c91ed778a0997c2029c152b18dc50e4fd, 4df78ff02629c7729168f0696a7a2123c389818d, 5.15.209, 6.1.175, 6.6.142, 6.12.92, 6.16 |
| Linux/Linuxgeneric | 6.16 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix a possible use-after-free when removing a bridge port When per-VLAN multicast snooping is enabled, the bridge iterates over all the bridge ports, disables the per-port multicast context on each port and enables the per-{port, VLAN} multicast contexts instead. The reverse happens when per-VLAN multicast snooping is disabled. When global multicast snooping is enabled, the bridge iterates over all the bridge ports and enables the per-port multicast context on each port. The reverse happens when multicast snooping is disabled. The above scheme can result in a situation where both types of contexts (per-port and per-{port, VLAN}) are enabled on a single bridge port: # ip link add name br1 up type bridge mcast_snooping 1 mcast_querier 1 vlan_filtering 1 # ip link add name dummy1 up master br1 type dummy # ip link set dev br1 type bridge mcast_vlan_snooping 1 # ip link set dev br1 type bridge mcast_snooping 0 # ip link set dev br1 type bridge mcast_snooping 1 This is not intended and it is a problem since the commit cited below. Prior to this commit, when removing a bridge port, br_multicast_disable_port() would disable the per-port multicast context and the per-{port, VLAN} multicast contexts would get disabled when flushing VLANs. After this commit, br_multicast_disable_port() only disables the per-port multicast context if per-VLAN multicast snooping is disabled. If both types of contexts were enabled on the port when it was removed, the per-port multicast context would remain enabled when freeing the bridge port, leading to a use-after-free [1]. Fix by preventing the bridge from enabling / disabling the per-port multicast contexts when toggling global multicast snooping if per-VLAN multicast snooping is enabled. [1] ODEBUG: free active (active state 0) object: ffff88810f8bda78 object type: timer_list hint: br_ip6_multicast_port_query_expired (net/bridge/br_multicast.c:1927) WARNING: lib/debugobjects.c:629 at debug_print_object+0x1b1/0x3e0, CPU#5: swapper/5/0 [...] Call Trace: <IRQ> __debug_check_no_obj_freed (lib/debugobjects.c:1116) kfree (mm/slub.c:2620 mm/slub.c:6250 mm/slub.c:6565) kobject_cleanup (lib/kobject.c:689) rcu_do_batch (kernel/rcu/tree.c:2617) rcu_core (kernel/rcu/tree.c:2869) handle_softirqs (kernel/softirq.c:622) __irq_exit_rcu (kernel/softirq.c:656 kernel/softirq.c:496 kernel/softirq.c:735) irq_exit_rcu (kernel/softirq.c:752) sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1061 (discriminator 47) arch/x86/kernel/apic/apic.c:1061 (discriminator 47)) </IRQ>
Quoted source text, attributed separately from HOL analysis.