CVE-2026-98285
Received Received - Intake

Linux Kernel VLAN Deletion Bug Fix

Vulnerability report for CVE-2026-98285, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: net: bridge: vlan: fix bugs caused by switchdev deletion errors Allowing switchdev to prevent vlan deletion and error out in __vlan_del could cause multiple different issues - inconsistent state, memory leaks when flushing, NULL pointer dereference on bridge error when flushing. It doesn't make sense to allow it to stop __vlan_del, so log the error and continue with software vlan deletion. This is also consistent with 8021q behaviour.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Linux Linux bf361ad38165939049a2649b1a0078f3268d4bd1
Linux Linux bf361ad38165939049a2649b1a0078f3268d4bd1
Linux Linux 4.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a bug in the bridge VLAN handling where switchdev errors could prevent proper VLAN deletion. This leads to inconsistent state, memory leaks during flushing, and potential NULL pointer dereferences when errors occur during bridge operations.

Impact Analysis

If exploited, this flaw could cause system instability, crashes, or resource exhaustion due to memory leaks. Network bridges relying on VLANs may malfunction, leading to connectivity issues or security gaps in network segmentation.

Mitigation Strategies

Update the Linux kernel to the latest stable version that includes the fix for this vulnerability. Monitor kernel logs for bridge vlan deletion errors to identify affected systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98285. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart