« Volver al listado

CVE-2026-97419

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

hsr: broadcast netlink notifications in the device's net namespace

The HSR generic netlink family sets .netnsok = true. HSR devices can live in network namespaces other than init_net.

Two async notifiers broadcast events with genlmsg_multicast(). They are hsr_nl_ringerror() and hsr_nl_nodedown(). That helper delivers only on the default genl socket in init_net. So the events always land in init_net. The network namespace of the device does not matter.

This has two effects. A listener in the device's own namespace never sees its own ring error and node down events.

Leer descripción completaMostrar menos

A privileged listener in init_net receives events from HSR devices in other namespaces. The payload carries the peer node MAC (HSR_A_NODE_ADDR) and the slave port ifindex (HSR_A_IFINDEX).

Switch both callers to genlmsg_multicast_netns(). Other families with .netnsok = true already do this. Examples are gtp, ovpn, team, batman-adv, netdev-genl, ethtool and handshake.

hsr_nl_ringerror() already has the slave port. It uses dev_net(port->dev). hsr_nl_nodedown() takes the namespace from the master port via hsr_port_get_hsr().

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97419",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f421436a591d34fa5279b54a96ac07d70250cc8d",
              "lessThan": "9f13023607f1e95bd098cc49052b0c8955d334f9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f421436a591d34fa5279b54a96ac07d70250cc8d",
              "lessThan": "798ccb12810a58a37264685b28ddf990ef49559c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f421436a591d34fa5279b54a96ac07d70250cc8d",
              "lessThan": "9bf45feee630be868ab54e3d0f3d430c07471f0e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f421436a591d34fa5279b54a96ac07d70250cc8d",
              "lessThan": "016b8eaca53bfd57e84ea28b5c9174c89d7679e1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f421436a591d34fa5279b54a96ac07d70250cc8d",
              "lessThan": "25b69f281cebe051a8e4ab19950a939c27ead1bc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f421436a591d34fa5279b54a96ac07d70250cc8d",
              "lessThan": "24b3f1a9982c176d05a523a4bb9314dca0db4488",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f421436a591d34fa5279b54a96ac07d70250cc8d",
              "lessThan": "a762fabd7ef9a6cc07258684138f9c3f078d0326",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/hsr/hsr_netlink.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/hsr/hsr_netlink.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:19.733",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/016b8eaca53bfd57e84ea28b5c9174c89d7679e1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/24b3f1a9982c176d05a523a4bb9314dca0db4488",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/25b69f281cebe051a8e4ab19950a939c27ead1bc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/798ccb12810a58a37264685b28ddf990ef49559c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9bf45feee630be868ab54e3d0f3d430c07471f0e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9f13023607f1e95bd098cc49052b0c8955d334f9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a762fabd7ef9a6cc07258684138f9c3f078d0326",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhsr: broadcast netlink notifications in the device's net namespace\n\nThe HSR generic netlink family sets .netnsok = true. HSR devices can\nlive in network namespaces other than init_net.\n\nTwo async notifiers broadcast events with genlmsg_multicast(). They\nare hsr_nl_ringerror() and hsr_nl_nodedown(). That helper delivers\nonly on the default genl socket in init_net. So the events always land\nin init_net. The network namespace of the device does not matter.\n\nThis has two effects. A listener in the device's own namespace never\nsees its own ring error and node down events. A privileged listener in\ninit_net receives events from HSR devices in other namespaces. The\npayload carries the peer node MAC (HSR_A_NODE_ADDR) and the slave port\nifindex (HSR_A_IFINDEX).\n\nSwitch both callers to genlmsg_multicast_netns(). Other families with\n.netnsok = true already do this. Examples are gtp, ovpn, team,\nbatman-adv, netdev-genl, ethtool and handshake.\n\nhsr_nl_ringerror() already has the slave port. It uses\ndev_net(port->dev). hsr_nl_nodedown() takes the namespace from the\nmaster port via hsr_port_get_hsr()."
    }
  ],
  "lastModified": "2026-10-03T11:17:54.000",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}