Linux Kernel - Mobile Bridge Functionality Vulnerability
CVE-2026-63988

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63988?

A vulnerability in the Linux kernel's bridge component allows improper use of locking mechanisms in specific functions, leading to potential system instability. The affected function, brport_store(), initially designed to manage bridge attributes, has expanded in its scope. This change requires a detailed revision of how locks are handled during operations. If the bridge locks are not correctly scoped, it can result in an operation that leads to sleeping in an invalid context, severely impacting system performance and reliability.

Affected Version(s)

Linux 78cd408356fe3edbac66598772fd347bf3e32c1f

Linux 78cd408356fe3edbac66598772fd347bf3e32c1f < 2f9cb30d97e45686f3119fff3b30f12259950910

Linux 78cd408356fe3edbac66598772fd347bf3e32c1f < 6d34594cc619d0d4b07d5afcad8b5984f3526dcf

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.