{"id":"CVE-2026-97419","published":"2026-09-24T17:17:19.733","lastModified":"2026-09-25T13:17:25.443","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhsr: broadcast netlink notifications in the device's net namespace\n\nThe HSR generic netlink family sets .netnsok = true. HSR devices can\nlive in network namespaces other than init_net.\n\nTwo async notifiers broadcast events with genlmsg_multicast(). They\nare hsr_nl_ringerror() and hsr_nl_nodedown(). That helper delivers\nonly on the default genl socket in init_net. So the events always land\nin init_net. The network namespace of the device does not matter.\n\nThis has two effects. A listener in the device's own namespace never\nsees its own ring error and node down events. A privileged listener in\ninit_net receives events from HSR devices in other namespaces. The\npayload carries the peer node MAC (HSR_A_NODE_ADDR) and the slave port\nifindex (HSR_A_IFINDEX).\n\nSwitch both callers to genlmsg_multicast_netns(). Other families with\n.netnsok = true already do this. Examples are gtp, ovpn, team,\nbatman-adv, netdev-genl, ethtool and handshake.\n\nhsr_nl_ringerror() already has the slave port. It uses\ndev_net(port->dev). hsr_nl_nodedown() takes the namespace from the\nmaster port via hsr_port_get_hsr().","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/24b3f1a9982c176d05a523a4bb9314dca0db4488","tags":[]},{"url":"https://git.kernel.org/stable/c/25b69f281cebe051a8e4ab19950a939c27ead1bc","tags":[]},{"url":"https://git.kernel.org/stable/c/a762fabd7ef9a6cc07258684138f9c3f078d0326","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}