Use-After-Free Vulnerability in Linux Kernel's Multicast Handling
CVE-2026-80842

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80842?

A vulnerability in the Linux kernel allows for a use-after-free scenario in multicast context management. This arises when the 'br_multicast_toggle_one_vlan()' function clears the multicast enabled flag prematurely under a lockless reader scenario. As a result, a VLAN's multicast context may be freed while still referenced by an ongoing read operation. This can lead to unpredictable behaviors such as memory corruption and potential system crashes, particularly affecting network operations involving IGMP packets and bridging. It’s crucial for administrators to apply relevant patches to mitigate this risk.

Affected Version(s)

Linux 7b54aaaf53cb784411426c64482af0435f7c845e < 3afaaee2f972aec9059110953adb62fa3cf5c4bd

Linux 7b54aaaf53cb784411426c64482af0435f7c845e < 22226a2c3b90f15b0925f1464470d3baa6c5677e

Linux 7b54aaaf53cb784411426c64482af0435f7c845e < 7c54fd8cfbcf371a5ef50db5c53fe6e85fb76686

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.