📌 이 취약점에 대해 확인된 사실
전부 발행처가 발표한 값입니다. 우리가 계산하거나 판단한 숫자는 하나도 없습니다.
악용 여부
심각도 (발행처 발표값)
악용 확률 (EPSS)
0.2%
📄 원문 그대로
아래 문장은 전부 발행처가 쓴 것입니다. 번역하지 않습니다 — 보안 문서의 오역은 조치를 바꿉니다.
취약점 설명 (NVD)
In the Linux kernel, the following vulnerability has been resolved: bonding: do not clear curr_active_slave prematurely when releasing all slaves When releasing all slaves during bond destruction (all == true), __bond_release_one() unconditionally clears bond->curr_active_slave to NULL in every iteration. If a backup slave is released before the active slave, bond_alb_deinit_slave() triggers rlb_teach_disabled_mac_on_primary(), which increments the active slave dev promiscuity counter and sets bond_info->primary_is_promisc = 1. Because bond->curr_active_slave was prematurely cleared to NULL when releasing the backup slave, the subsequent iteration releasing the active slave evaluates oldcurrent as NULL, so bond_change_active_slave(bond, NULL) is skipped. Consequently, bond_alb_handle_active_change() is never called to decrement the promiscuity counter, permanently leaking promiscuous mode on the physical device after bond teardown. When oldcurrent == slave, bond_change_active_slave(bond, NULL) already sets bond->curr_active_slave to NULL. We only need to avoid selecting a new active slave when all == true. Replace the if (all) branch with if (!all && oldcurrent == slave).
참고
악용 확률 변화
우리가 매일 저장한 EPSS 스냅샷입니다. 원본은 전날 값만 주므로, 이 표는 수집을 시작한 이후만 보여줍니다.
| 기준일 | 확률 | 백분위 |
|---|---|---|
| 2026-09-29 | 0.17% | 5.4% |
| 2026-09-27 | 0.17% | 5.4% |
| 2026-09-26 | 0.17% | 5.4% |