-

CVE-2026-97476

rds: filter RDS_INFO_* getsockopt by caller's netns

In the Linux kernel, the following vulnerability has been resolved:

rds: filter RDS_INFO_* getsockopt by caller's netns

The RDS_INFO_* family of getsockopt(2) options reads several
file-scope global lists that are not per-netns:

  rds_sock_info / rds6_sock_info,
  rds_sock_inc_info / rds6_sock_inc_info        -> rds_sock_list
  rds_tcp_tc_info / rds6_tcp_tc_info            -> rds_tcp_tc_list
  rds_conn_info / rds6_conn_info,
  rds_conn_message_info_cmn (for the *_SEND_MESSAGES and
  *_RETRANS_MESSAGES variants),
  rds_for_each_conn_info (for RDS_INFO_IB_CONNECTIONS)
                                                -> rds_conn_hash[]

The handlers do not filter by the caller's network namespace.
rds_info_getsockopt() has no netns or capable() check, and
rds_create() has no capable() check, so AF_RDS is reachable from
an unprivileged user namespace. As a result, an unprivileged
caller in a fresh user_ns plus netns can read the bound address
and sock inode of every RDS socket on the host, the peer address
of incoming messages on every RDS socket on the host, the peer
address and TCP sequence numbers of every rds-tcp connection on
the host, and the peer address and RDS sequence numbers of every
RDS connection on the host.

The rds-tcp transport is reachable from a non-initial netns (see
rds_set_transport()), so a one-shot init_net gate at
rds_info_getsockopt() would deny legitimate per-netns visibility
to rds-tcp callers. Instead, filter at each handler by comparing
the netns of the caller's socket to the netns of the list entry,
or to rds_conn_net(conn) for connection paths. Only copy entries
whose netns matches the caller. Counters (RDS_INFO_COUNTERS) are
aggregate statistics and remain global.

Reproducer (KASAN VM, rds and rds_tcp loaded): an AF_RDS socket
binds 127.0.0.1:4242 in init_net as root. A child process enters
a fresh user_ns plus netns and opens AF_RDS there, then calls
getsockopt(SOL_RDS, RDS_INFO_SOCKETS). Before this change, the
child sees the init_net socket. After this change, the child
sees zero entries.

Drop the rds_sock_count, rds_tcp_tc_count, and rds6_tcp_tc_count
globals. v2 used them for the size precheck and lens->nr; v3
replaced the precheck with a per-ns count from a first pass over
the list, so the globals have no remaining readers. The matching
increments and decrements in rds_create()/rds_destroy_sock() and
rds_tcp_set_callbacks()/rds_tcp_restore_callbacks() go away with
them. Reported by the kernel test robot under clang W=1.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4
Version < 64ca5839916176c3451f61a2c7178033423c67d7
Status affected
Version 639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4
Version < 8b04dda272c30d46834bb03dd2895b08c090483b
Status affected
Version 639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4
Version < f05142d0eeaa6e8227511c88e10a2b8fe7a78fc4
Status affected
Version 639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4
Version < 65fae4b42269dbea7e3842ae4dd0786162c6248e
Status affected
Version 639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4
Version < 093f172296d32499ffac7809629b206178776eb6
Status affected
Version 639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4
Version < c4081e49ebe0e3160c4b70ec7639494792dee206
Status affected
Version 639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4
Version < c96a5209dda666004b8ee1ed7f0d493d09a4f200
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.30
Status affected
Version 0
Version < 2.6.30
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/093f172296d32499ffac7809629b206178776eb6
https://git.kernel.org/stable/c/c4081e49ebe0e3160c4b70ec7639494792dee206
https://git.kernel.org/stable/c/c96a5209dda666004b8ee1ed7f0d493d09a4f200
https://git.kernel.org/stable/c/64ca5839916176c3451f61a2c7178033423c67d7
https://git.kernel.org/stable/c/65fae4b42269dbea7e3842ae4dd0786162c6248e
https://git.kernel.org/stable/c/8b04dda272c30d46834bb03dd2895b08c090483b
https://git.kernel.org/stable/c/f05142d0eeaa6e8227511c88e10a2b8fe7a78fc4