PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72389 Linux CVE debrief

A use-after-free vulnerability was found in the Linux kernel's bridge module. The STP topology change timer was not properly shut down when the bridge was administratively down, leading to a potential use-after-free when the bridge was deleted. This vulnerability has been resolved in the Linux kernel. Affected systems may be vulnerable to potential use-after-free errors if the bridge module is not properly shut down. The vulnerability was caused by missing checks for 'IFF_UP' before arming the STP timers, which could lead to a use-after-free when the bridge was deleted. Further review is needed to determine the full scope of affected systems and potential impact. Defenders should verify system configurations, review logs for suspicious activity, and ensure the bridge module is properly shut down when not in use.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers and users who rely on the bridge module, as well as security teams and vulnerability management teams responsible for ensuring the security of Linux-based systems. System administrators and operators who manage Linux systems with the bridge module enabled should also be aware of this vulnerability and take steps to mitigate it.

Technical summary

The Linux kernel's bridge module has a use-after-free vulnerability. The STP topology change timer is not properly shut down when the bridge is administratively down, leading to a potential use-after-free when the bridge is deleted. This vulnerability has been resolved in the Linux kernel. Affected systems may be vulnerable to potential use-after-free errors if the bridge module is not properly shut down.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the Linux kernel patch to fix the use-after-free vulnerability
  • Ensure the bridge module is properly shut down when not in use
  • Monitor the system for potential use-after-free errors
  • Perform a thorough review of system configurations to identify potential exposure
  • Implement compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions and retest remediated assets to ensure the vulnerability is fully resolved
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record was published on 2026-08-15T06:22:12.397Z. The NVD entry is currently Received. The vulnerability was resolved in the Linux kernel. Further review is needed to determine the full scope of affected systems and potential impact. Defenders should verify system configurations, review logs for suspicious activity, and ensure the bridge module is properly shut down when not in use.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72389 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72389

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72389 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72389

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/297a747f59bff6573196d7236178144d66524e68

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2a00517db8de4be7df3d483b215c5544fb30a191

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/39283907a25e5caf0f2bd2947f6e56644b01e2b7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/40cbfa3a28e0919469d1b086629bb3ce38a83593

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4c40eec06eeac37c58e47a6058eb32901218d5d4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b4b3458ef88df4798632619f018791d4344bcd92

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c86579b0a2d201792bcb59316629f4ba4758cfc8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.