Junglewise Threat Intelligence

CVE-2026-53353: Linux Kernel HSR race condition in hsr_addr_is_self

CVE-2026-53353 · Severity: info · CVSS 0 · Published 2026-07-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A technical issue was identified in the Linux kernel's High-availability Seamless Redundancy (HSR) networking component. During the process of removing a network interface, a race condition could trigger an internal system warning. This issue does not result in data loss or unauthorized access, but rather corrects an erroneous assumption in the code that caused unnecessary system alerts during normal cleanup operations.

Technical details

The vulnerability (or rather, kernel bug) is a race condition in the High-availability Seamless Redundancy (HSR) protocol implementation. Specifically, hsr_addr_is_self() assumed that hsr->self_node would always be present if the device was reachable. However, hsr_dellink() clears hsr->self_node before unregister_netdevice_many() completes, creating a window where a user or system process can still find and interact with the device while the self-node is NULL. This triggered a WARN_ONCE() kernel warning. The fix involves removing the incorrect WARN_ONCE() and gracefully handling the NULL self-node state. This is primarily a stability/logging issue rather than a security exploit.

Affected products

  • Linux Linux Kernel f266a683a480 and later

Timeline

  • 2026-05-30: patched: Initial patch submitted by Kuniyuki Iwashima
  • 2026-07-01: advisory: CVE-2026-53353 published by NVD

References

Related threats