Вернуться к предупреждениям о безопасности

Kernel Root CVE (CVE-2026-72389)

CVE-2026-72389 (bridge-stp-uaf) is a use-after-free in the Linux kernel's bridge Spanning Tree Protocol timers that lets a local unprivileged user who can configure a network bridge escalate to root. CloudLinux has published a kernel update and mitigation; DirectAdmin server owners running CloudLinux should apply it, and kernels on other distributions should be updated as fixes land.

High 7.8 CVSS
CloudLinux DirectAdmin

Команда обновления по умолчанию

cd /usr/local/directadmin/custombuild && ./build update_versions

Что это значит по лицензии SharedLicense

Any local user with bridge configuration rights can turn that into full root on the host — a serious exposure on container hosts and servers where tenants can create bridges.

CloudLinux specific take on it:


		
			
				
					
						
					
				
			
			
				
					
						bridge-stp-uaf (CVE-2026-72389) local root vulnerability: kernel update and mitigation for CloudLinux - CloudLinux
					
				

				📋 TL;DR — last updated September 10, 2026, 16:20 UTC bridge-stp-uaf (CVE-2026-72389, CVSS 7.0, Moderate per Red Hat) is a vulnerability in the Linux kernel’s bridge Spanning Tree Protocol timers. A local unprivileged user who can configure a network bridge can turn it into root on the host. The...

				
					
						
							
						
					
					blog.cloudlinux.com
				
			
		
	

Часто задаваемые вопросы

What is CVE-2026-72389?
It is a use-after-free vulnerability in the Linux kernel's bridge Spanning Tree Protocol timer handling, nicknamed bridge-stp-uaf. A local unprivileged user who can configure a network bridge can exploit it to become root. CloudLinux notes Red Hat rates it Moderate with a CVSS of 7.0.
Who can exploit CVE-2026-72389?
It requires local access and the ability to configure a network bridge — for example, container hosts or servers where tenants can set up bridges. Hosting accounts without bridge capabilities are much less exposed, but the kernel update should still be applied.
How do I fix CVE-2026-72389 on CloudLinux?
Apply CloudLinux's kernel update (or KernelCare live patch if installed) per their advisory, then confirm the running kernel includes the bridge-stp-uaf fix. DirectAdmin components are managed separately with CustomBuild, but the kernel itself comes from the OS vendor.
Is CVE-2026-72389 being exploited in the wild?
No active exploitation has been reported. CloudLinux published the kernel update and a mitigation with a TL;DR dated September 10, 2026, and their disclosure mentions no exploitation.

Проверьте систему на уязвимости

Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.

Проверьте свою систему