PT-2026-104967 · Azure Linux · Kernel

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
hsr: broadcast netlink notifications in the device's net namespace
The HSR generic netlink family sets .netnsok = true. HSR devices can live in network namespaces other than init net.
Two async notifiers broadcast events with genlmsg multicast(). They are hsr nl ringerror() and hsr nl nodedown(). That helper delivers only on the default genl socket in init net. So the events always land in init net. The network namespace of the device does not matter.
This has two effects. A listener in the device's own namespace never sees its own ring error and node down events. A privileged listener in init net receives events from HSR devices in other namespaces. The payload carries the peer node MAC (HSR A NODE ADDR) and the slave port ifindex (HSR A IFINDEX).
Switch both callers to genlmsg multicast netns(). Other families with .netnsok = true already do this. Examples are gtp, ovpn, team, batman-adv, netdev-genl, ethtool and handshake.
hsr nl ringerror() already has the slave port. It uses dev net(port->dev). hsr nl nodedown() takes the namespace from the master port via hsr port get hsr().
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-103916

Affected Products

Kernel