8.8

CVE-2026-68294

net: qrtr: restrict socket creation to the initial network namespace

In the Linux kernel, the following vulnerability has been resolved:

net: qrtr: restrict socket creation to the initial network namespace

QRTR keeps its entire port and node state in module-global variables
that are not partitioned per network namespace: qrtr_local_nid is a
single global node id (always 1) and qrtr_ports is a single global
xarray. qrtr_port_lookup() and qrtr_local_enqueue() operate on that
global state with no network-namespace check, and qrtr_create() places
no restriction on the namespace a socket is created in.

As a result an unprivileged process that creates an AF_QIPCRTR socket
in a separate network namespace, e.g. via
unshare(CLONE_NEWUSER | CLONE_NEWNET), can send QRTR datagrams -
including control-plane messages such as QRTR_TYPE_NEW_SERVER - to QRTR
sockets owned by another namespace, and vice versa. The receiving
socket sees such a message as coming from node id 1, indistinguishable
from a legitimate local client, breaking the isolation that network
namespaces are expected to provide.

QRTR is a transport to global hardware endpoints (the modem and other
remote processors) and has no per-namespace semantics; its in-kernel
name service already creates its socket in init_net only. Confine the
socket family to the initial network namespace, as other
non-namespace-aware socket families do (see llc_ui_create() and the
ieee802154 socket code).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version bdabad3e363d825ddf9679dd431cca0b2c30f881
Version < 7814f6a3415cad38aa8d6dfc573df778260d66aa
Status affected
Version bdabad3e363d825ddf9679dd431cca0b2c30f881
Version < 2d22b94a154ccb9755dddfff802fe3e2b1adbab5
Status affected
Version bdabad3e363d825ddf9679dd431cca0b2c30f881
Version < 8d351fe0654a20c9f95a61b05d24ebe6d4be3fbb
Status affected
Version bdabad3e363d825ddf9679dd431cca0b2c30f881
Version < 4b95e1f0d6e6342c427cb341ee18a894b146b789
Status affected
Version bdabad3e363d825ddf9679dd431cca0b2c30f881
Version < f488116df769bdaf89c93371350e49e12133e70f
Status affected
Version bdabad3e363d825ddf9679dd431cca0b2c30f881
Version < 8150c48fb978e01689f94ed80148f8a7499ae571
Status affected
Version bdabad3e363d825ddf9679dd431cca0b2c30f881
Version < 659b9b4f194bb56b9903cc95e786ef1d438baa7d
Status affected
Version bdabad3e363d825ddf9679dd431cca0b2c30f881
Version < 3b536db8fb32da9e9c62f2bb45e2e319331f0426
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.7
Status affected
Version 0
Version < 4.7
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4b95e1f0d6e6342c427cb341ee18a894b146b789
https://git.kernel.org/stable/c/f488116df769bdaf89c93371350e49e12133e70f
https://git.kernel.org/stable/c/8150c48fb978e01689f94ed80148f8a7499ae571
https://git.kernel.org/stable/c/659b9b4f194bb56b9903cc95e786ef1d438baa7d
https://git.kernel.org/stable/c/3b536db8fb32da9e9c62f2bb45e2e319331f0426
https://git.kernel.org/stable/c/2d22b94a154ccb9755dddfff802fe3e2b1adbab5
https://git.kernel.org/stable/c/7814f6a3415cad38aa8d6dfc573df778260d66aa
https://git.kernel.org/stable/c/8d351fe0654a20c9f95a61b05d24ebe6d4be3fbb