bridge: cfm: reject invalid CCM interval at configuration time
Summary
| CVE | CVE-2026-64537 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-27 21:17:05 UTC |
| Updated | 2026-07-27 21:17:05 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: reject invalid CCM interval at configuration time ccm_tx_work_expired() re-arms itself via queue_delayed_work() using the configured exp_interval converted by interval_to_us(). When exp_interval is BR_CFM_CCM_INTERVAL_NONE or out of range, interval_to_us() returns 0, causing the worker to fire immediately in a tight loop that allocates skbs until OOM. Fix this by validating exp_interval at configuration time: - Constrain IFLA_BRIDGE_CFM_CC_CONFIG_EXP_INTERVAL to the valid range [BR_CFM_CCM_INTERVAL_3_3_MS, BR_CFM_CCM_INTERVAL_10_MIN] in the netlink policy so userspace cannot set an invalid value. - Reject starting CCM TX in br_cfm_cc_ccm_tx() when exp_interval has not yet been configured (defaults to 0 from kzalloc). |
Risk And Classification
EPSS: 0.001720000 probability, percentile 0.068950000 (date 2026-07-29)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 2be665c3940d367e0a2a8128eb4985ce323f99a3 2870056a78961e0fecd652362ee9d3fcfd24a8a6 git | Not specified |
| CNA | Linux | Linux | affected 2be665c3940d367e0a2a8128eb4985ce323f99a3 f0f5eb59a97ece0d85de8cfa95dc18c609302a8b git | Not specified |
| CNA | Linux | Linux | affected 2be665c3940d367e0a2a8128eb4985ce323f99a3 53788b134519e995699ea3721969c96a08d64575 git | Not specified |
| CNA | Linux | Linux | affected 2be665c3940d367e0a2a8128eb4985ce323f99a3 b42aeb58317f12024734759ff745856b53948873 git | Not specified |
| CNA | Linux | Linux | affected 2be665c3940d367e0a2a8128eb4985ce323f99a3 a090880c1f544589427e5b7050c40fb211ccecb4 git | Not specified |
| CNA | Linux | Linux | affected 2be665c3940d367e0a2a8128eb4985ce323f99a3 865643640b5b5c4579b32d7a55ac9ad648362eaa git | Not specified |
| CNA | Linux | Linux | affected 2be665c3940d367e0a2a8128eb4985ce323f99a3 f3e02edd8322b31b8e6517faa6ba053bf29d1e26 git | Not specified |
| CNA | Linux | Linux | affected 5.11 | Not specified |
| CNA | Linux | Linux | unaffected 5.11 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.212 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.178 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.145 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.97 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.40 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.5 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/f3e02edd8322b31b8e6517faa6ba053bf29d1e26 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/53788b134519e995699ea3721969c96a08d64575 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b42aeb58317f12024734759ff745856b53948873 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/865643640b5b5c4579b32d7a55ac9ad648362eaa | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f0f5eb59a97ece0d85de8cfa95dc18c609302a8b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/a090880c1f544589427e5b7050c40fb211ccecb4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/2870056a78961e0fecd652362ee9d3fcfd24a8a6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.