← All Advisories

CVE-2026-97615

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97615

Key Details

CVECVE-2026-97615
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: bridge: use option bits for CFM/MRP frame handlers

CFM and MRP register a global br_frame_type whose hlist_node is linked

into the per-bridge frame_type_list when the first MEP/MRP instance is

created. Enabling the protocol on multiple bridges therefore inserts the

same node into multiple lists. Unregistering it on one bridge then

corrupts list state belonging to another.

These handlers can only be installed once per bridge, and they are

uncommon. Track their per-bridge enable state with net_bridge option

bits, which already live on the Rx hot cache line, and dispatch the

matching handler directly from the receive path. Check both bits

together first as an unlikely case.

Remove the generic frame_type_list and br_frame_type helpers, which

have had no other users since CFM and MRP were added. That shrinks

struct net_bridge by 8 bytes and drops the list walk from the fast

path. When neither protocol is compiled in, BR_CFM_MRP_OPTS is 0 and

the compiler prunes the branch. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97615
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97615