Skip to content
ThreatCluster

Critical Use-After-Free Vulnerability in Linux Kernel STP Disclosed

First seen 6 Aug 2026, 14:07 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 7, 2026 at 12:56 UTC
  • A critical use-after-free vulnerability in Linux kernel's STP implementation has been disclosed.
  • A proof-of-concept (PoC) is available, increasing the risk of exploitation.
  • The flaw affects systems using the Linux kernel's network bridge functionality.

A use-after-free vulnerability has been identified in the Linux kernel's bridge implementation affecting the Spanning Tree Protocol (STP). This flaw allows for timer structures to reference freed memory, potentially enabling control-flow hijacking. The vulnerability arises when a bridge is administratively down while STP is enabled, leading to a situation where timers are not properly deleted. A proof-of-concept (PoC) has been released, increasing the risk of exploitation. The issue affects systems using the Linux kernel's network bridge functionality. Security teams are urged to assess their environments for potential exposure. The vulnerability has not been assigned a CVE number yet, but it is considered critical due to the PoC availability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 46d ago How this analysis works

Timeline

2026-08-05
Vulnerability disclosed
A use-after-free vulnerability in the Linux kernel bridge STP implementation was disclosed, detailing its exploitability.
Reddit
2026-08-06
PoC released
A proof-of-concept for the use-after-free vulnerability was released, demonstrating potential control-flow hijacking.
Gbhackers

More articles in this cluster (2)