-

CVE-2026-97419

hsr: broadcast netlink notifications in the device's net namespace

In the Linux kernel, the following vulnerability has been resolved:

hsr: broadcast netlink notifications in the device's net namespace

The HSR generic netlink family sets .netnsok = true. HSR devices can
live in network namespaces other than init_net.

Two async notifiers broadcast events with genlmsg_multicast(). They
are hsr_nl_ringerror() and hsr_nl_nodedown(). That helper delivers
only on the default genl socket in init_net. So the events always land
in init_net. The network namespace of the device does not matter.

This has two effects. A listener in the device's own namespace never
sees its own ring error and node down events. A privileged listener in
init_net receives events from HSR devices in other namespaces. The
payload carries the peer node MAC (HSR_A_NODE_ADDR) and the slave port
ifindex (HSR_A_IFINDEX).

Switch both callers to genlmsg_multicast_netns(). Other families with
.netnsok = true already do this. Examples are gtp, ovpn, team,
batman-adv, netdev-genl, ethtool and handshake.

hsr_nl_ringerror() already has the slave port. It uses
dev_net(port->dev). hsr_nl_nodedown() takes the namespace from the
master port via hsr_port_get_hsr().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f421436a591d34fa5279b54a96ac07d70250cc8d
Version < 9f13023607f1e95bd098cc49052b0c8955d334f9
Status affected
Version f421436a591d34fa5279b54a96ac07d70250cc8d
Version < 798ccb12810a58a37264685b28ddf990ef49559c
Status affected
Version f421436a591d34fa5279b54a96ac07d70250cc8d
Version < 9bf45feee630be868ab54e3d0f3d430c07471f0e
Status affected
Version f421436a591d34fa5279b54a96ac07d70250cc8d
Version < 016b8eaca53bfd57e84ea28b5c9174c89d7679e1
Status affected
Version f421436a591d34fa5279b54a96ac07d70250cc8d
Version < 25b69f281cebe051a8e4ab19950a939c27ead1bc
Status affected
Version f421436a591d34fa5279b54a96ac07d70250cc8d
Version < 24b3f1a9982c176d05a523a4bb9314dca0db4488
Status affected
Version f421436a591d34fa5279b54a96ac07d70250cc8d
Version < a762fabd7ef9a6cc07258684138f9c3f078d0326
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.13
Status affected
Version 0
Version < 3.13
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/25b69f281cebe051a8e4ab19950a939c27ead1bc
https://git.kernel.org/stable/c/24b3f1a9982c176d05a523a4bb9314dca0db4488
https://git.kernel.org/stable/c/a762fabd7ef9a6cc07258684138f9c3f078d0326
https://git.kernel.org/stable/c/016b8eaca53bfd57e84ea28b5c9174c89d7679e1
https://git.kernel.org/stable/c/798ccb12810a58a37264685b28ddf990ef49559c
https://git.kernel.org/stable/c/9bf45feee630be868ab54e3d0f3d430c07471f0e
https://git.kernel.org/stable/c/9f13023607f1e95bd098cc49052b0c8955d334f9