Kernel Root CVE (CVE-2026-72389)
CVE-2026-72389 (bridge-stp-uaf) is a use-after-free in the Linux kernel's bridge Spanning Tree Protocol timers that lets a local unprivileged user who can configure a network bridge escalate to root. CloudLinux has published a kernel update and mitigation; DirectAdmin server owners running CloudLinux should apply it, and kernels on other distributions should be updated as fixes land.
CMD de actualización por defecto
cd /usr/local/directadmin/custombuild && ./build update_versions
Lo que esto significa bajo una licencia de SharedLicense
Any local user with bridge configuration rights can turn that into full root on the host — a serious exposure on container hosts and servers where tenants can create bridges.
CloudLinux specific take on it:
bridge-stp-uaf (CVE-2026-72389) local root vulnerability: kernel update and mitigation for CloudLinux - CloudLinux
📋 TL;DR — last updated September 10, 2026, 16:20 UTC bridge-stp-uaf (CVE-2026-72389, CVSS 7.0, Moderate per Red Hat) is a vulnerability in the Linux kernel’s bridge Spanning Tree Protocol timers. A local unprivileged user who can configure a network bridge can turn it into root on the host. The...
blog.cloudlinux.com
Preguntas frecuentes
What is CVE-2026-72389?
Who can exploit CVE-2026-72389?
How do I fix CVE-2026-72389 on CloudLinux?
Is CVE-2026-72389 being exploited in the wild?
Comprueba tu sistema en busca de vulnerabilidades
Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.
Comprueba tu sistema