CVE-2025-38248: bridge: mcast: Fix use-after-free during router port configuration
bridge: mcast: Fix use-after-free during router port configuration
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Fix the use-after-free in bridge multicast router port configuration by applying the kernel patch titled "bridge: mcast: Fix use-after-free during router port configuration" so that deleting/disabling multicast snooping properly disables relevant contexts and removes the port from the global/per-VLAN router lists during port deletion and VLAN deletion.
Linux kernel net: bridge (mcast) per-VLAN multicast snooping / router port configuration = Apply upstream fix by ensuring the port cannot remain in global/per-VLAN router port lists after multicast snooping is disabled or during VLAN/port deletion
Event History
Frequently Asked Questions
What is the severity of CVE-2025-38248?
CVE-2025-38248 is classified as a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2025-38248?
To fix CVE-2025-38248, update your Linux kernel to the latest stable version provided by your distribution.
What is the impact of CVE-2025-38248?
CVE-2025-38248 may lead to a use-after-free condition during multicast router port configuration, potentially causing system instability.
Which versions of the Linux kernel are affected by CVE-2025-38248?
CVE-2025-38248 affects various versions of the Linux kernel prior to the fix being applied.
Is CVE-2025-38248 related to any specific Linux subsystems?
CVE-2025-38248 is specifically related to the bridge subsystem in the Linux kernel, which handles multicast routing.