CVE-2024-40921

In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: pass vlan group directly to br_mst_vlan_set_state Pass the already obtained vlan group pointer to br_mst_vlan_set_state() instead of dereferencing it again. Each caller has already correctly dereferenced it for their context. This change is required for the following suspicious RCU dereference fix. No functional changes intended.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc3:*:*:*:*:*:*

History

03 Nov 2025, 22:17

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html -

17 Sep 2025, 15:44

Type Values Removed Values Added
First Time Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/09f4337c27f5bdeb8646a6db91488cc2f7d537ff - () https://git.kernel.org/stable/c/09f4337c27f5bdeb8646a6db91488cc2f7d537ff - Patch
References () https://git.kernel.org/stable/c/36c92936e868601fa1f43da6758cf55805043509 - () https://git.kernel.org/stable/c/36c92936e868601fa1f43da6758cf55805043509 - Patch
References () https://git.kernel.org/stable/c/a6cc9e9a651b9861efa068c164ee62dfba68c6ca - () https://git.kernel.org/stable/c/a6cc9e9a651b9861efa068c164ee62dfba68c6ca - Patch
References () https://git.kernel.org/stable/c/d2dc02775fc0c4eacaee833a0637e5958884a8e5 - () https://git.kernel.org/stable/c/d2dc02775fc0c4eacaee833a0637e5958884a8e5 - Patch
CPE cpe:2.3:o:linux:linux_kernel:6.10:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.10:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

Information

Published : 2024-07-12 13:15

Updated : 2025-11-03 22:17


NVD link : CVE-2024-40921

Mitre link : CVE-2024-40921

CVE.ORG link : CVE-2024-40921


JSON object : View

Products Affected

linux

  • linux_kernel