7.8

CVE-2026-68335

rds: drop incoming messages that cross network namespace boundaries

In the Linux kernel, the following vulnerability has been resolved:

rds: drop incoming messages that cross network namespace boundaries

rds_find_bound() looks up the destination socket using a global
rhashtable keyed solely on (addr, port, scope_id).  Network namespaces
are not part of the key, so a sender in netns A can deliver an incoming
message (inc) to a socket that lives in a different netns B.

When this happens, inc->i_conn points to an rds_connection whose c_net
is netns A, but the receiving rs lives in netns B.  Once the child
process that created netns A exits, cleanup_net() calls
rds_loop_exit_net() -> rds_loop_kill_conns() -> rds_conn_destroy(),
freeing that connection.  If the survivor socket in netns B still holds
the inc, any subsequent dereference of inc->i_conn is a use-after-free.

There are two dangerous sites in rds_clear_recv_queue():
  1. inc->i_conn->c_lcong (offset 88 of freed rds_connection, size 200)
     read via rds_recv_rcvbuf_delta() -- confirmed by KASAN.
  2. inc->i_conn->c_trans->inc_free(inc) (function pointer at offset 80)
     called via rds_inc_put() when the inc refcount reaches zero -- same
     race window, potential call-through-freed-object primitive.

The bug is reachable from unprivileged user namespaces
(CLONE_NEWUSER + CLONE_NEWNET), available since Linux 3.8.

Fix this by rejecting the delivery in rds_recv_incoming() when the
socket returned by rds_find_bound() belongs to a different network
namespace than the connection that carried the message.  Use the
existing rds_conn_net() / sock_net() helpers and net_eq() for the
comparison.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version c809195f5523dd4d09403bbb1c9732d548aa0d1e
Version < 742ff6f02545212e991cd8b45011e40d2c2ef25a
Status affected
Version c809195f5523dd4d09403bbb1c9732d548aa0d1e
Version < abff41fd928328bbf3dda1140beb2e61fa424ccd
Status affected
Version c809195f5523dd4d09403bbb1c9732d548aa0d1e
Version < 03c574112e5d066df0ddce36d7438e850bcf3050
Status affected
Version c809195f5523dd4d09403bbb1c9732d548aa0d1e
Version < 1e2e2d9806944fe485824d617c8b7c78116c22db
Status affected
Version c809195f5523dd4d09403bbb1c9732d548aa0d1e
Version < cfb3ce07b705e486e022a2f2b1242b48f13981ff
Status affected
Version c809195f5523dd4d09403bbb1c9732d548aa0d1e
Version < 9591042533140dfe6608d9344806d567dcd39d02
Status affected
Version c809195f5523dd4d09403bbb1c9732d548aa0d1e
Version < 0f8690e3869109cd5803ccb400889d20a0b54e0e
Status affected
Version c809195f5523dd4d09403bbb1c9732d548aa0d1e
Version < 5521ae71e32a8069ed4ca6e792179dc57bc43ab2
Status affected
Version c827073c95fde388bc65fe5227f944eaf859b9f0
Status affected
Version 4.17.19
Version < 4.18
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.18
Status affected
Version 0
Version < 4.18
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.034
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1e2e2d9806944fe485824d617c8b7c78116c22db
https://git.kernel.org/stable/c/cfb3ce07b705e486e022a2f2b1242b48f13981ff
https://git.kernel.org/stable/c/9591042533140dfe6608d9344806d567dcd39d02
https://git.kernel.org/stable/c/0f8690e3869109cd5803ccb400889d20a0b54e0e
https://git.kernel.org/stable/c/5521ae71e32a8069ed4ca6e792179dc57bc43ab2
https://git.kernel.org/stable/c/03c574112e5d066df0ddce36d7438e850bcf3050
https://git.kernel.org/stable/c/742ff6f02545212e991cd8b45011e40d2c2ef25a
https://git.kernel.org/stable/c/abff41fd928328bbf3dda1140beb2e61fa424ccd