CloudLinux specific take on it:
blog.cloudlinux.com
bridge-stp-uaf (CVE-2026-72389) local root vulnerability: kernel update and mitigation for CloudLinux - CloudLinux
📋 TL;DR — last updated September 10, 2026, 16:20 UTC bridge-stp-uaf (CVE-2026-72389, CVSS 7.0, Moderate per Red Hat) is a vulnerability in the Linux kernel’s bridge Spanning Tree Protocol timers. A local unprivileged user who can configure a network bridge can turn it into root on the host. The...
blog.cloudlinux.com