
PoC Released for Linux Kernel Bridge STP Use-After-Free Flaw Enabling Control-Flow Hijacking
A proof-of-concept (PoC) has been released for a use-after-free vulnerability affecting the Linux kernel’s software bridge implementation, specifically its Spanning Tree Protocol (STP) timer handling. The flaw can leave queued STP timers pointing to freed bridge memory, potentially creating a control-flow hijacking primitive under suitable conditions. Researchers n132 and Sven Sze reportedly identified and submitted […]
The post PoC Released for Linux Kernel Bridge STP Use-After-Free Flaw Enabling Control-Flow Hijacking appeared first on Cyber Security News.