SB2026092827 - Memory leak in Linux kernel hsr
Published: September 28, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Memory leak (CVE-ID: CVE-2026-100071)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource cleanup in HSR device setup error handling when receiving frames after an RX handler has been registered and device setup subsequently fails. A remote attacker can send frames during HSR device setup to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0a340ffd96943a49a78e367efac9517ca767d99b
- https://git.kernel.org/stable/c/49b01f2939abc676a6f9a118f07a10110ee5f683
- https://git.kernel.org/stable/c/65702339b3e9fd792f65d4b740928798194d86ce
- https://git.kernel.org/stable/c/7f16289b91eb316f170a6bd22d32e6c632f6a5b6
- https://git.kernel.org/stable/c/e691eee886871b933d772ffc76d66c80b4c0a25e
- https://git.kernel.org/stable/c/f7289e3492f2694dccd3d79287e0e31879b58650