Back

HIGH

net: hsr: Fix potential use-after-free

Published Oct 21, 2024

Description

The skb is delivered to netif_rx() which may free it, after calling this, dereferencing skb may trigger use-after-free.

Affected products

Remediation

Red Hat statement

This issue is considered to be a moderate impact flaw, as the reproduction for this seems only to cause a DOS.

Red Hat mitigation

To mitigate this issue, prevent the `hsr` kernel module from loading. Create a file named `/etc/modprobe.d/blacklist-hsr.conf` with the following content: `blacklist hsr` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect: `dracut -f -v` `reboot` Disabling the `hsr` module may impact systems that rely on High-availability Seamless Redundancy networking.

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Oct 21, 2024
Updated Aug 5, 2026
Reserved Aug 22, 2024

CISA Vulnrichment

Updated Oct 22, 2024

NVD

Status Modified
Modified Aug 4, 2026

Red Hat

Severity Moderate
Public date Oct 21, 2024
Bugzilla 2320699

ENISA EUVD

Assigner Linux
Published Oct 21, 2024
Updated Aug 5, 2026

GitHub

No data