{"id":"CVE-2026-97419","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nhsr: broadcast netlink notifications in the device's net namespace\n\nThe HSR generic netlink family sets .netnsok = true","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nhsr: broadcast netlink notifications in the device's net namespace\n\nThe HSR generic netlink family sets .netnsok = true. HSR devices can\nlive in network namespaces othe…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 25b69f281cebe051a8e4ab19950a939c27ead1bc","Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 24b3f1a9982c176d05a523a4bb9314dca0db4488","Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a762fabd7ef9a6cc07258684138f9c3f078d0326","Linux < 6.12.111","Linux < 6.18.53","Linux (all versions)"],"published":"2026-09-24","updated":"2026-09-25","sourceUpdated":"2026-09-25T13:17:25.443","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97419","references":[{"url":"https://git.kernel.org/stable/c/24b3f1a9982c176d05a523a4bb9314dca0db4488","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/25b69f281cebe051a8e4ab19950a939c27ead1bc","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a762fabd7ef9a6cc07258684138f9c3f078d0326","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-24T16:47:15.886Z","slug":"CVE-2026-97419","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nhsr: broadcast netlink notifications in the device's net namespace\n\nThe HSR generic netlink family sets .netnsok = true. HSR devices can\nlive in network namespaces other than init_net.\n\nTwo async notifiers broadcast events with genlmsg_multicast(). They\nare hsr_nl_ringerror() and hsr_nl_nodedown(). That helper delivers\nonly on the default genl socket in init_net. So the events always land\nin init_net. The network namespace of the device does not matter.\n\nThis has two effects. A listener in the device's own namespace never\nsees its own ring error and node down events. A privileged listener in\ninit_net receives events from HSR devices in other namespaces. The\npayload carries the peer node MAC (HSR_A_NODE_ADDR) and the slave port\nifindex (HSR_A_IFINDEX).\n\nSwitch both callers to genlmsg_multicast_netns(). Other families with\n.netnsok = true already do this. Examples are gtp, ovpn, team,\nbatman-adv, netdev-genl, ethtool and handshake.\n\nhsr_nl_ringerror() already has the slave port. It uses\ndev_net(port->dev). hsr_nl_nodedown() takes the namespace from the\nmaster port via hsr_port_get_hsr().\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}