

Affected Environment
Linux kernel versions 5.10 through 7.1 running the network bridge module, particularly where multicast-to-unicast was previously enabled on affected systems.
Threat Overview
A use-after-free in bridge multicast fast-leave handling lets a local attacker crash affected systems or escalate privileges to root.
Exposure Timeline
Disclosed 25 August 2026 and issued 26 August 2026, with patches already available across all seven affected kernel branches.
Attack Surface
Local access to systems where multicast-to-unicast was previously enabled then disabled, leaving stale port group pointers reachable during fast leave operations.
Technical Root Cause
br_multicast_leave_group continues iterating after br_multicast_del_pg deletes a matching port group entry, dereferencing a stale next pointer.
Exploitation Pathway
A local attacker triggers a fast leave event on a bridge that previously used multicast-to-unicast, corrupting memory to crash the system or gain root.
Operational Impact
Successful exploitation crashes affected systems or grants an attacker root privileges, threatening availability and full local system control.
Strategic Impact
Rated Critical for all government and business entity sizes given the widespread use of the Linux kernel network bridge module.
Required Mitigation
Apply vendor kernel patches immediately, upgrade software and firmware on network assets, and apply the Principle of Least Privilege.
Incident Response Guidance
Use vulnerability management tools to confirm kernel versions, apply advanced application control, and keep endpoint security signatures current.
References
NCSC Ireland, NVD, CVE.org, Linux kernel stable Git repository, Security Online.
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




