A vulnerability was found in Linux Kernel up to 6.1.94/6.6.34/6.9.5. It has been declared as critical. Affected by this vulnerability is the function br_mst_vlan_set_state. The manipulation leads to null pointer dereference.

This vulnerability is known as CVE-2024-40921. Access to the local network is required for this attack. There is no exploit available.

It is recommended to upgrade the affected component.