CVE-2026-68301

In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix memory leak on slave unregistration by removing synced VLANs When an HSR master device is brought UP, it auto-adds VLAN 0 via vlan_vid0_add(), which propagates VID 0 to its slave devices (slave A and B). If a slave device is later unregistered while HSR is active (e.g., during netns cleanup or interface destruction), hsr_del_port() is called to detach the slave port from the HSR master. However, hsr_del_port() currently does not delete the VLAN IDs that were synced to the slave device by HSR. As a result, the slave device retains a refcount on VID 0 (and any other synced VLANs). When the slave device is destroyed, its vlan_info / vlan_vid_info structure remains allocated, leading to a memory leak. Fix this by calling vlan_vids_del_by_dev(port->dev, master->dev) in hsr_del_port() before unlinking slave A or slave B ports, matching the propagation logic in hsr_ndo_vlan_rx_add_vid() / hsr_ndo_vlan_rx_kill_vid() and the cleanup behavior in bonding and team drivers.

Package Linux Kernel
Published 2026-08-10
Last modified 2026-08-19
Patch available
Yes

Affected versions

Linux kernel versions 5.15.194, 6.1.153, 6.6.107, 6.12.48, 6.13 and later are affected. Fixed in 5.15.216, 6.1.183, 6.6.148, 6.12.101, 6.18.42, 7.1.6, 7.2 and their respective stable series.

Affected from
≥ 5.15.194 ≥ 6.1.153 ≥ 6.6.107 ≥ 6.12.48 ≥ 6.13
Fixed in
✓ 5.15.216 5.15.x ✓ 6.1.183 6.1.x ✓ 6.6.148 6.6.x ✓ 6.12.101 6.12.x ✓ 6.18.42 6.18.x ✓ 7.1.6 7.1.x ✓ 7.2

Frequently asked questions

  • What is CVE-2026-68301?

    CVE-2026-68301 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.15.194 onward and has been patched in 5.15.216, 6.1.183, 6.6.148 and others. CVE-2026-68301 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-68301?

    Yes. CVE-2026-68301 has been patched. Fixed versions include 5.15.216, 6.1.183, 6.6.148 and others. If you are running Linux kernel 5.15.194 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-68301 actively exploited?

    No. CVE-2026-68301 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.