PoC Released for Linux Kernel STP Use-After-Free Vulnerability
ID: fad525ce-44a5-56b5-875e-e23e9a1e35cb
STIX ID: report--fad525ce-44a5-56b5-875e-e23e9a1e35cb
Feed Name: GBHackers
A proof-of-concept has been published for a Linux kernel use-after-free in the software bridge (net/bridge) STP timers that can leave queued timer callbacks pointing to freed bridge memory, potentially allowing an attacker to replace timer function pointers and achieve kernel control-flow hijacking. The issue arises from inconsistent cleanup when deleting a downed bridge with STP-enabled ports remaining in LEARNING state; Linux has issued a patch (commit 2a00517db8de4be7df3d483b215c5544fb30a191) and administrators should apply it or update kernels.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
