Executive brief
A vulnerability exists in the Linux kernel's networking component responsible for High-availability Seamless Redundancy (HSR) and Parallel Redundancy Protocol (PRP). These protocols are typically used in industrial automation and critical infrastructure to ensure network reliability. An exploit could cause the system to crash (denial of service) when it fails to allocate memory for incoming network traffic, potentially disrupting industrial operations or safety systems.
Technical details
A NULL pointer dereference vulnerability exists in the prp_get_untagged_frame() function within the net/hsr/hsr_forward.c component of the Linux kernel. The root cause is a missing check for the return value of __pskb_copy(); when this function fails to allocate memory and returns NULL, a subsequent call to skb_clone() dereferences the NULL pointer, leading to a general protection fault and system crash. This can be triggered by incoming PRP network frames during periods of memory exhaustion. The issue has been patched in multiple stable kernel branches by adding the necessary NULL check.
Affected products
- Linux Linux Kernel f266a683a480 and later
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6
- Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.6
- Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.6
Timeline
- 2025-11-29: disclosed: Vulnerability reported and patch authored
- 2025-12-04: patched: Initial patch committed to stable tree
- 2026-01-13: advisory: CVE published
References
- https://git.kernel.org/stable/c/1742974c24a9c1f1fd2e5edca0cbaccb720b397a
- https://git.kernel.org/stable/c/188e0fa5a679570ea35474575e724d8211423d17
- https://git.kernel.org/stable/c/3ce95a57d8a1f0e20b637cdeddaaed81831ca819
- https://git.kernel.org/stable/c/6220d38a08f8837575cd8f830928b49a3a5a5095
- https://git.kernel.org/stable/c/7be6d25f4d974e44918ba3a5d58ebb9d36879087
- https://git.kernel.org/stable/c/8f289fa12926aae44347ca7d490e216555d8f255
- https://git.kernel.org/stable/c/c851e43b88b40bb7c20176c51cbf4f8c8d960dd9