REDHAT-BUG-2481989: Medium severity The Linux Kernel Community Linux Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: use a stable FDB dst snapshot in RCU readers
Local FDB entries can be rewritten in place by fdbdeletelocal(), which updates f->dst to another port or to NULL while keeping the entry alive. Several bridge RCU readers inspect f->dst, including brfdbfillbuf() through the brforwardread() sysfs path.
These readers currently load f->dst multiple times and can therefore observe inconsistent values across the check and later dereference. In brfdbfillbuf(), this means a concurrent local-FDB update can change f->dst after the NULL check and before the portno dereference, leading to a NULL-ptr-deref.
Fix this by taking a single READONCE() snapshot of f->dst in each affected RCU reader and using that snapshot for the rest of the access sequence. Also publish the in-place f->dst updates in fdbdeletelocal() with WRITEONCE() so the readers and writer use matching access patterns.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2481989?
The severity of REDHAT-BUG-2481989 is medium, rated at 4.
What is the main issue described in REDHAT-BUG-2481989?
REDHAT-BUG-2481989 describes a vulnerability in the Linux kernel related to unstable FDB dst snapshots during RCU reads.
How do I fix REDHAT-BUG-2481989?
To fix REDHAT-BUG-2481989, you should apply the latest patches released by the Linux Kernel Community.
Who is affected by REDHAT-BUG-2481989?
Any users or systems utilizing the affected versions of the Linux kernel with bridge networking features are at risk due to REDHAT-BUG-2481989.
When was REDHAT-BUG-2481989 published?
REDHAT-BUG-2481989 was published on May 27, 2026.