CVE-2024-40921

In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: pass vlan group directly to br_mst_vlan_set_state Pass the already obtained vlan group pointer to br_mst_vlan_set_state() instead of dereferencing it again. Each caller has already correctly dereferenced it for their context. This change is required for the following suspicious RCU dereference fix. No functional changes intended.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc3:*:*:*:*:*:*

History

17 Sep 2025, 15:44

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:6.10:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE NVD-CWE-noinfo
References () https://git.kernel.org/stable/c/09f4337c27f5bdeb8646a6db91488cc2f7d537ff - () https://git.kernel.org/stable/c/09f4337c27f5bdeb8646a6db91488cc2f7d537ff - Patch
References () https://git.kernel.org/stable/c/36c92936e868601fa1f43da6758cf55805043509 - () https://git.kernel.org/stable/c/36c92936e868601fa1f43da6758cf55805043509 - Patch
References () https://git.kernel.org/stable/c/a6cc9e9a651b9861efa068c164ee62dfba68c6ca - () https://git.kernel.org/stable/c/a6cc9e9a651b9861efa068c164ee62dfba68c6ca - Patch
References () https://git.kernel.org/stable/c/d2dc02775fc0c4eacaee833a0637e5958884a8e5 - () https://git.kernel.org/stable/c/d2dc02775fc0c4eacaee833a0637e5958884a8e5 - Patch

21 Nov 2024, 09:31

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net: bridge: mst: pasar grupo vlan directamente a br_mst_vlan_set_state Pase el puntero del grupo vlan ya obtenido a br_mst_vlan_set_state() en lugar de desreferenciarlo nuevamente. Cada persona que llama ya lo ha desreferenciado correctamente para su contexto. Este cambio es necesario para la siguiente corrección sospechosa de desreferencia de RCU. No se pretenden cambios funcionales.
References () https://git.kernel.org/stable/c/09f4337c27f5bdeb8646a6db91488cc2f7d537ff - () https://git.kernel.org/stable/c/09f4337c27f5bdeb8646a6db91488cc2f7d537ff -
References () https://git.kernel.org/stable/c/36c92936e868601fa1f43da6758cf55805043509 - () https://git.kernel.org/stable/c/36c92936e868601fa1f43da6758cf55805043509 -
References () https://git.kernel.org/stable/c/a6cc9e9a651b9861efa068c164ee62dfba68c6ca - () https://git.kernel.org/stable/c/a6cc9e9a651b9861efa068c164ee62dfba68c6ca -
References () https://git.kernel.org/stable/c/d2dc02775fc0c4eacaee833a0637e5958884a8e5 - () https://git.kernel.org/stable/c/d2dc02775fc0c4eacaee833a0637e5958884a8e5 -

12 Jul 2024, 16:34

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-12 13:15

Updated : 2025-09-17 15:44


NVD link : CVE-2024-40921

Mitre link : CVE-2024-40921

CVE.ORG link : CVE-2024-40921


JSON object : View

Products Affected

linux

  • linux_kernel