- Sources: SSD Secure Disclosure advisory, HN discussion
- Summary: A bridge left administratively down with kernel STP enabled and a port driven into the LEARNING state arms periodic STP timers with no IFF_UP guard, and only
br_stp_disable_bridge, reached from br_dev_stop on an UP to DOWN transition, deletes those timers synchronously. Deleting the bridge link instead runs br_dev_delete, which never calls it, and unregister_netdevice_many skips ndo_stop for a device already down, so the net_device is freed with a timer still queued on a per-CPU timer base and a slab use-after-free lands in the kmalloc-cg-8k cache. When that timer base next runs, call_timer_fn executes the timer's function field, so refilling the freed slot yields attacker-controlled control flow. Researchers n132 and sven sze reported it at TyphoonPWN 2026 and it is fixed in mainline commit 2a00517db8de4be7df3d483b215c5544fb30a191. - Why it matters: Exploit code is public, the advisory dates to 2026-08-05, and the advisory scopes affected versions as any kernel prior to the fix commit, with the entry filed under the TyphoonPWN 2026 Linux privilege escalation category.
- Follow-up: This continues the tracked run of Linux local-root exploits with public proofs of concept. Track distribution backports of the fix commit.
send feedback on this story