In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). (CVE-2026-53353)
A vulnerability in the Linux kernel's hsr (High-availability Seamless Redundancy) module was addressed by removing a WARN_ONCE() call in the hsr_addr_is_self() function. The warning was triggered due to an incorrect assumption about the state of hsr->self_node during device removal, which could cause a kernel warning or soft lockup. This issue does not impact confidentiality or integrity but can cause an availability impact due to kernel warnings or potential soft lockups.
AI Analysis
Technical Summary
The vulnerability involves the hsr_addr_is_self() function in the Linux kernel's hsr module, where a WARN_ONCE() warning was issued based on an incorrect assumption about the presence of hsr->self_node during device removal. The hsr->self_node is cleared in hsr_del_self_node(), called from hsr_dellink(), and there is a timing window where the device is still visible but hsr->self_node is cleared, causing the warning. The fix removes the WARN_ONCE() call to prevent this warning and potential soft lockup conditions.
Potential Impact
The vulnerability does not affect confidentiality or integrity but can cause availability issues by triggering kernel warnings and potential soft lockups. This may lead to system instability or degraded performance during the affected operations.
Mitigation Recommendations
A fix has been applied in the Linux kernel to remove the WARN_ONCE() call in hsr_addr_is_self(). Users should update to a Linux kernel version that includes this fix. Patch status is not explicitly provided, so users should consult the vendor or Linux kernel release notes for the specific fixed version.
In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). (CVE-2026-53353)
Description
A vulnerability in the Linux kernel's hsr (High-availability Seamless Redundancy) module was addressed by removing a WARN_ONCE() call in the hsr_addr_is_self() function. The warning was triggered due to an incorrect assumption about the state of hsr->self_node during device removal, which could cause a kernel warning or soft lockup. This issue does not impact confidentiality or integrity but can cause an availability impact due to kernel warnings or potential soft lockups.
CVSS v3.1
Score 5.5medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability involves the hsr_addr_is_self() function in the Linux kernel's hsr module, where a WARN_ONCE() warning was issued based on an incorrect assumption about the presence of hsr->self_node during device removal. The hsr->self_node is cleared in hsr_del_self_node(), called from hsr_dellink(), and there is a timing window where the device is still visible but hsr->self_node is cleared, causing the warning. The fix removes the WARN_ONCE() call to prevent this warning and potential soft lockup conditions.
Potential Impact
The vulnerability does not affect confidentiality or integrity but can cause availability issues by triggering kernel warnings and potential soft lockups. This may lead to system instability or degraded performance during the affected operations.
Mitigation Recommendations
A fix has been applied in the Linux kernel to remove the WARN_ONCE() call in hsr_addr_is_self(). Users should update to a Linux kernel version that includes this fix. Patch status is not explicitly provided, so users should consult the vendor or Linux kernel release notes for the specific fixed version.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-j8j2-8gr5-pf32
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53353"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a6150e99c2644c7f8da230d
Added to database: 07/22/2026, 23:23:21 UTC
Last enriched: 07/22/2026, 23:38:23 UTC
Last updated: 07/31/2026, 19:24:47 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.