CVE-2024-40921: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: pass vlan group directly to br_mst_vlan_set_state Pass the already obtained vlan group pointer to br_mst_vlan_set_state() instead of dereferencing it again. Each caller has already correctly dereferenced it for their context. This change is required for the following suspicious RCU dereference fix. No functional changes intended.

Affected products

  • Linux Linux Kernel: from 6.1.93, before 6.1.95 (fixed in 6.1.95); from 6.6.33, before 6.6.35 (fixed in 6.6.35); from 6.8.12, before 6.9 (fixed in 6.9); from 6.9.3, before 6.9.6 (fixed in 6.9.6); version 6.10 only

Published 2024-07-12. Last modified 2026-06-17.