SB2026092827 - Memory leak in Linux kernel hsr



SB2026092827 - Memory leak in Linux kernel hsr

Published: September 28, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026092827
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Partial DoS

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Memory leak (CVE-ID: CVE-2026-100071)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper resource cleanup in HSR device setup error handling when receiving frames after an RX handler has been registered and device setup subsequently fails. A remote attacker can send frames during HSR device setup to cause a denial of service.


Remediation

Install update from vendor's website.