CVE-2024-40920: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: fix suspicious rcu usage in br_mst_set_state I converted br_mst_set_state to RCU to avoid a vlan use-after-free but forgot to change the vlan group dereference helper. Switch to vlan group RCU deref helper to fix the suspicious rcu usage warning.
Affected products
- Linux Linux Kernel: from 6.1.93, before 6.1.95 (fixed in 6.1.95); from 6.6.33, before 6.6.35 (fixed in 6.6.35); from 6.8.12, before 6.9 (fixed in 6.9); from 6.9.3, before 6.9.6 (fixed in 6.9.6); version 6.10 only
Published 2024-07-12. Last modified 2026-08-04.