cbcvebase.
CVE-2024-40920
published 2024-07-12

CVE-2024-40920: In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: fix suspicious rcu usage in br_mst_set_state I converted br_mst_set_state…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.7th percentile
In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: fix suspicious rcu usage in br_mst_set_state I converted br_mst_set_state to RCU to avoid a vlan use-after-free but forgot to change the vlan group dereference helper. Switch to vlan group RCU deref helper to fix the suspicious rcu usage warning.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= 3a7c1661ae1383364cd6092d851f5e5da64d476b < 546ceb1dfdac866648ec959cbc71d9525bd73462546ceb1dfdac866648ec959cbc71d9525bd73462
linuxlinux>= 4488617e5e995a09abe4d81add5fb165674edb59 < 7caefa2771722e65496d85b62e1dc4442b7d13457caefa2771722e65496d85b62e1dc4442b7d1345
linuxlinux>= 6.1.93 < 6.1.956.1.95
linuxlinux>= 6.6.33 < 6.6.356.6.35
linuxlinux>= 6.8.12 < 6.96.9
linuxlinux>= 6.9.3 < 6.9.66.9.6
linuxlinux>= 8ca9a750fc711911ef616ceb627d07357b04545e < caaa2129784a04dcade0ea92c12e6ff90bbd23d8caaa2129784a04dcade0ea92c12e6ff90bbd23d8
linuxlinux>= e43dd2b1ec746e105b7db5f9ad6ef14685a615a4 < 406bfc04b01ee47e4c626f77ecc7d9f85135b166406bfc04b01ee47e4c626f77ecc7d9f85135b166
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 6.1.93 < 6.1.956.1.95
linuxlinux_kernel>= 6.6.33 < 6.6.356.6.35
linuxlinux_kernel>= 6.8.12 < 6.96.9
linuxlinux_kernel>= 6.9.3 < 6.9.66.9.6

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.