Exposure of Resource to Wrong Sphere in Linux kernel - CVE-2026-97419
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local privileged user to disclose sensitive information.
The vulnerability exists due to improper network namespace isolation in HSR generic netlink notification handling when broadcasting ring error and node down events. A local privileged user can listen for notifications from HSR devices in other network namespaces in init_net to disclose sensitive information.
The notifications expose the peer node MAC address and slave port interface index.