CVE-2026-98301
Received Received - Intake

Linux Kernel RCU Sleep in Bridge MST State Handling

Vulnerability report for CVE-2026-98301, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: move switchdev call outside rcu This is a follow-up of one of sashiko's pre-existing bug reports. br_mst_set_state() calls switchdev_port_attr_set() for nonzero MSTIs while holding rcu_read_lock() which invokes the blocking switchdev notifier chain and may sleep. Nonzero MSTI changes come from netlink with rtnl held. Move the switchdev call before entering the rcu section and assert that rtnl is held. The call cannot be deferred because netlink needs its error and extack. Also DSA reads the old bridge MST state during the callback and checks it. A deferred callback will be late and will see the updated state.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 13 associated CPEs
Vendor Product Version / Range
Linux Linux 8ca9a750fc711911ef616ceb627d07357b04545e
Linux Linux 4488617e5e995a09abe4d81add5fb165674edb59
Linux Linux 3a7c1661ae1383364cd6092d851f5e5da64d476b
Linux Linux 3a7c1661ae1383364cd6092d851f5e5da64d476b
Linux Linux 3a7c1661ae1383364cd6092d851f5e5da64d476b
Linux Linux 3a7c1661ae1383364cd6092d851f5e5da64d476b
Linux Linux a2b01e65d9ba8af2bb086d3b7288ca53a07249ac
Linux Linux e43dd2b1ec746e105b7db5f9ad6ef14685a615a4
Linux Linux 6.1.93
Linux Linux 6.6.33
Linux Linux 6.8.12
Linux Linux 6.9.3
Linux Linux 6.10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a race condition in the bridge multicast spanning tree (MST) code. The function br_mst_set_state() calls switchdev_port_attr_set() while holding an RCU read lock, which can block and sleep. This violates RCU locking rules since blocking operations are not allowed under RCU read lock. The fix moves the switchdev call outside the RCU section and ensures proper locking is maintained.

Detection Guidance

This vulnerability is specific to the Linux kernel's bridge module and involves a race condition in the MST (Multiple Spanning Tree) state handling. Detection requires checking kernel logs for bridge-related errors or kernel panics related to MST state changes. Commands like 'dmesg | grep -i bridge' or 'journalctl -k | grep -i bridge' may help identify issues.

Impact Analysis

This vulnerability could lead to kernel deadlocks or crashes if exploited, causing system instability or denial of service. Systems using Linux kernel networking with bridge MST features may experience unexpected behavior or failures. Attackers on the local network could potentially trigger this issue via crafted network traffic.

Mitigation Strategies

Apply the latest kernel update that includes the fix for this issue. If updating is not immediately possible, avoid using MST features in the bridge module until patched. Monitor kernel logs for related errors and restrict network changes that might trigger the vulnerable code path.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98301. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart