Linux Kernel - Mobile Bridge Functionality Vulnerability
CVE-2026-63988
What is CVE-2026-63988?
A vulnerability in the Linux kernel's bridge component allows improper use of locking mechanisms in specific functions, leading to potential system instability. The affected function, brport_store(), initially designed to manage bridge attributes, has expanded in its scope. This change requires a detailed revision of how locks are handled during operations. If the bridge locks are not correctly scoped, it can result in an operation that leads to sleeping in an invalid context, severely impacting system performance and reliability.
Affected Version(s)
Linux 78cd408356fe3edbac66598772fd347bf3e32c1f
Linux 78cd408356fe3edbac66598772fd347bf3e32c1f < 2f9cb30d97e45686f3119fff3b30f12259950910
Linux 78cd408356fe3edbac66598772fd347bf3e32c1f < 6d34594cc619d0d4b07d5afcad8b5984f3526dcf