Linux Kernel Out-of-Bounds Access Vulnerability in HSR Supervision Frame Handling

Vulnerability

A potential out-of-bounds access vulnerability has been identified in the Linux kernel's Handling of HSR (High-availability Seamless Redundancy) supervision frames. This issue arises because the entire TLV (Type-Length-Value) header is not properly linearized before being accessed. A truncated frame could lead to an out-of-bounds access, creating a risk of memory corruption or other unintended behavior.

Impact

Exploitation of this vulnerability could lead to out-of-bounds memory access, potentially causing memory corruption or allowing for arbitrary code execution.

Reproduction

The vulnerability can be reproduced by sending a truncated HSR supervision frame that does not fully comply with the expected TLV header length. This can be done by manipulating the frame's data to create a partial TLV header, which will then be processed by the kernel without proper validation, leading to an out-of-bounds access.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been patched. Instructions for downloading the updated kernel can be found on the official Linux kernel website.

Added: Jul 19, 2026, 6:58 PM
Updated: Jul 19, 2026, 6:58 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.7
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.