Use-After-Free Vulnerability in Linux Kernel's Multicast Handling
CVE-2026-80842
What is CVE-2026-80842?
A vulnerability in the Linux kernel allows for a use-after-free scenario in multicast context management. This arises when the 'br_multicast_toggle_one_vlan()' function clears the multicast enabled flag prematurely under a lockless reader scenario. As a result, a VLAN's multicast context may be freed while still referenced by an ongoing read operation. This can lead to unpredictable behaviors such as memory corruption and potential system crashes, particularly affecting network operations involving IGMP packets and bridging. It’s crucial for administrators to apply relevant patches to mitigate this risk.
Affected Version(s)
Linux 7b54aaaf53cb784411426c64482af0435f7c845e < 3afaaee2f972aec9059110953adb62fa3cf5c4bd
Linux 7b54aaaf53cb784411426c64482af0435f7c845e < 22226a2c3b90f15b0925f1464470d3baa6c5677e
Linux 7b54aaaf53cb784411426c64482af0435f7c845e < 7c54fd8cfbcf371a5ef50db5c53fe6e85fb76686