In the Linux kernel, the following vulnerability has been resolved:
net: bridge: mst: pass vlan group directly to br_mst_vlan_set_state
Pass the already obtained vlan group pointer to br_mst_vlan_set_state()
instead of dereferencing it again. Each caller has already correctly
dereferenced it for their context. This change is required for the
following suspicious RCU dereference fix. No functional changes
intended.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 17 Sep 2025 15:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.10:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.10:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.10:rc3:*:*:*:*:*:* | 
Fri, 20 Dec 2024 08:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 12 Sep 2024 08:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Wed, 11 Sep 2024 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Linux
Published: 2024-07-12T12:25:02.907Z
Updated: 2025-05-04T12:57:15.850Z
Reserved: 2024-07-12T12:17:45.582Z
Link: CVE-2024-40921
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-02T04:39:55.321Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-07-12T13:15:15.060
Modified: 2025-09-17T15:44:50.067
Link: CVE-2024-40921
 Redhat
                        Redhat