CVE-2025-38248
Linux Linux, linux kernel
In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix use-after-free during router port configuration The bridge maintains a global list of ports behind which a multicast router resides. The list is consulted during forwarding to ensure multicast packets are forwarded to these ports even if the ports are not member in the matching MDB entry. When per-VLAN multicast snooping is enabled, the per-port multicast context is disabled on each port and the port is removed from the global router port list: # ip link add name br1 up type bridge vlan_filtering 1 mcast_...
- CVSS
- 7.8
- EPSS
- 0.25% 16.8% percentile
- CISA KEV
- Not listed
- Published
- 2025.07.09