ThreatCluster

Critical Use-After-Free Vulnerability in Linux Kernel STP Disclosed

First seen 6 Aug 2026, 14:07 UTC RedditGbhackers 78% similarity 70

Article Content

Browse articles
ThreatCluster

A use-after-free vulnerability has been identified in the Linux kernel's bridge implementation affecting the Spanning Tree Protocol (STP). This flaw allows for timer structures to reference freed memory, potentially enabling control-flow hijacking. The vulnerability arises when a bridge is administratively down while STP is enabled, leading to a situation where timers are not properly deleted. A proof-of-concept (PoC) has been released, increasing the risk of exploitation. The issue affects systems using the Linux kernel's network bridge functionality. Security teams are urged to assess their environments for potential exposure. The vulnerability has not been assigned a CVE number yet, but it is considered critical due to the PoC availability.

Key Points: • A critical use-after-free vulnerability in Linux kernel's STP implementation has been disclosed. • A proof-of-concept (PoC) is available, increasing the risk of exploitation. • The flaw affects systems using the Linux kernel's network bridge functionality.

ThreatCluster AI How this analysis works

Timeline

2026-08-05
Vulnerability disclosed
A use-after-free vulnerability in the Linux kernel bridge STP implementation was disclosed, detailing its exploitability.
Reddit
2026-08-06
PoC released
A proof-of-concept for the use-after-free vulnerability was released, demonstrating potential control-flow hijacking.
Gbhackers

Community

Browse all →