« Volver al listado

CVE-2026-46086

Estado: En análisisMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

net: bridge: use a stable FDB dst snapshot in RCU readers

Local FDB entries can be rewritten in place by `fdb_delete_local()`, which updates `f->dst` to another port or to `NULL` while keeping the entry alive. Several bridge RCU readers inspect `f->dst`, including `br_fdb_fillbuf()` through the `brforward_read()` sysfs path.

These readers currently load `f->dst` multiple times and can therefore observe inconsistent values across the check and later dereference. In `br_fdb_fillbuf()`, this means a concurrent local-FDB update can change `f->dst` after the NULL check and before the `port_no` dereference, leading to a NULL-ptr-deref.

Leer descripción completaMostrar menos

Fix this by taking a single `READ_ONCE()` snapshot of `f->dst` in each affected RCU reader and using that snapshot for the rest of the access sequence. Also publish the in-place `f->dst` updates in `fdb_delete_local()` with `WRITE_ONCE()` so the readers and writer use matching access patterns.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-46086",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "960b589f86c74ce582922fcb996103271081f4de",
              "lessThan": "c502fa9f094cb03d1d1685c71e2105ab359bc2b8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "960b589f86c74ce582922fcb996103271081f4de",
              "lessThan": "a6ae4511c07b91f597e461406c6330f0d4ff810e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "960b589f86c74ce582922fcb996103271081f4de",
              "lessThan": "1406c4e0ed1eaf8a29801ab1163d00fb7ee4359a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "960b589f86c74ce582922fcb996103271081f4de",
              "lessThan": "0b9e4bbfb7c949151e3acd44ed4aa33614d2e110",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "960b589f86c74ce582922fcb996103271081f4de",
              "lessThan": "81af4137a30c4c2dc694dea8cacb180bd66000ef",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "960b589f86c74ce582922fcb996103271081f4de",
              "lessThan": "5424e678f9b304e148cf5dcc047cffc7a56a3bb5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "960b589f86c74ce582922fcb996103271081f4de",
              "lessThan": "9a2d9d4e657b23dc21f24cf139e3aeff0b61341f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "960b589f86c74ce582922fcb996103271081f4de",
              "lessThan": "df4601653201de21b487c3e7fffd464790cab808",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/bridge/br_arp_nd_proxy.c",
            "net/bridge/br_fdb.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.259",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.210",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.176",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.140",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.86",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.27",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.0.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.*"
            },
            {
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/bridge/br_arp_nd_proxy.c",
            "net/bridge/br_fdb.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-05-27T14:17:30.080",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0b9e4bbfb7c949151e3acd44ed4aa33614d2e110",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1406c4e0ed1eaf8a29801ab1163d00fb7ee4359a",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5424e678f9b304e148cf5dcc047cffc7a56a3bb5",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/81af4137a30c4c2dc694dea8cacb180bd66000ef",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9a2d9d4e657b23dc21f24cf139e3aeff0b61341f",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a6ae4511c07b91f597e461406c6330f0d4ff810e",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c502fa9f094cb03d1d1685c71e2105ab359bc2b8",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/df4601653201de21b487c3e7fffd464790cab808",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
      "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: use a stable FDB dst snapshot in RCU readers\n\nLocal FDB entries can be rewritten in place by `fdb_delete_local()`, which\nupdates `f->dst` to another port or to `NULL` while keeping the entry\nalive. Several bridge RCU readers inspect `f->dst`, including\n`br_fdb_fillbuf()` through the `brforward_read()` sysfs path.\n\nThese readers currently load `f->dst` multiple times and can therefore\nobserve inconsistent values across the check and later dereference.\nIn `br_fdb_fillbuf()`, this means a concurrent local-FDB update can change\n`f->dst` after the NULL check and before the `port_no` dereference,\nleading to a NULL-ptr-deref.\n\nFix this by taking a single `READ_ONCE()` snapshot of `f->dst` in each\naffected RCU reader and using that snapshot for the rest of the access\nsequence. Also publish the in-place `f->dst` updates in `fdb_delete_local()`\nwith `WRITE_ONCE()` so the readers and writer use matching access patterns."
    }
  ],
  "lastModified": "2026-09-08T09:18:07.390",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "381832F6-7D7D-4333-9276-B44B01372277",
              "versionEndExcluding": "5.10.259",
              "versionStartIncluding": "3.14.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E938CDF-D1C4-43D0-98DC-9E11B6B55801",
              "versionEndExcluding": "5.15.210",
              "versionStartIncluding": "5.11"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C4446623-5F2B-4DD8-8666-9FAAC285A757",
              "versionEndExcluding": "6.1.176",
              "versionStartIncluding": "5.16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1A92866-F406-43B5-B2D1-CFC274753E9D",
              "versionEndExcluding": "6.6.140",
              "versionStartIncluding": "6.2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "55DA1C62-9991-451E-B8A8-E0004E00F789",
              "versionEndExcluding": "6.12.86",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A10AC84F-C058-47D5-85B4-E6E51A613B74",
              "versionEndExcluding": "6.18.27",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDB78D6D-22C3-4154-B0D0-94AF1CE5C2E3",
              "versionEndExcluding": "7.0.4",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:3.14:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "851B1505-0318-49F4-8D7C-196BE04FF173"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:3.14:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1795E18E-AE30-4230-809F-E40317FB96BD"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:3.14:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F91AF02-7C23-4888-A580-07C166BE8128"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:3.14:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "61A7DB5C-EB54-4D4A-AB38-8060F13C8779"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:3.14:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FF2C86B-7087-4EFC-A256-3AF313C25325"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:3.14:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14AC6A73-D01C-44F4-9821-BAE9600E72D5"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:3.14:rc8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "055557BE-1FE9-45F5-8A95-F8D3C9B031E4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}