rds: drop incoming messages that cross network namespace boundaries
Summary
| CVE | CVE-2026-68335 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 13:20:23 UTC |
| Updated | 2026-08-10 13:20:23 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
rds: drop incoming messages that cross network namespace boundaries
rds_find_bound() looks up the destination socket using a global
rhashtable keyed solely on (addr, port, scope_id). Network namespaces
are not part of the key, so a sender in netns A can deliver an incoming
message (inc) to a socket that lives in a different netns B.
When this happens, inc->i_conn points to an rds_connection whose c_net
is netns A, but the receiving rs lives in netns B. Once the child
process that created netns A exits, cleanup_net() calls
rds_loop_exit_net() -> rds_loop_kill_conns() -> rds_conn_destroy(),
freeing that connection. If the survivor socket in netns B still holds
the inc, any subsequent dereference of inc->i_conn is a use-after-free.
There are two dangerous sites in rds_clear_recv_queue():
1. inc->i_conn->c_lcong (offset 88 of freed rds_connection, size 200)
read via rds_recv_rcvbuf_delta() -- confirmed by KASAN.
2. inc->i_conn->c_trans->inc_free(inc) (function pointer at offset 80)
called via rds_inc_put() when the inc refcount reaches zero -- same
race window, potential call-through-freed-object primitive.
The bug is reachable from unprivileged user namespaces
(CLONE_NEWUSER + CLONE_NEWNET), available since Linux 3.8.
Fix this by rejecting the delivery in rds_recv_incoming() when the
socket returned by rds_find_bound() belongs to a different network
namespace than the connection that carried the message. Use the
existing rds_conn_net() / sock_net() helpers and net_eq() for the
comparison. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected c809195f5523dd4d09403bbb1c9732d548aa0d1e 1e2e2d9806944fe485824d617c8b7c78116c22db git |
Not specified |
| CNA |
Linux |
Linux |
affected c809195f5523dd4d09403bbb1c9732d548aa0d1e cfb3ce07b705e486e022a2f2b1242b48f13981ff git |
Not specified |
| CNA |
Linux |
Linux |
affected c809195f5523dd4d09403bbb1c9732d548aa0d1e 9591042533140dfe6608d9344806d567dcd39d02 git |
Not specified |
| CNA |
Linux |
Linux |
affected c809195f5523dd4d09403bbb1c9732d548aa0d1e 0f8690e3869109cd5803ccb400889d20a0b54e0e git |
Not specified |
| CNA |
Linux |
Linux |
affected c809195f5523dd4d09403bbb1c9732d548aa0d1e 5521ae71e32a8069ed4ca6e792179dc57bc43ab2 git |
Not specified |
| CNA |
Linux |
Linux |
affected c827073c95fde388bc65fe5227f944eaf859b9f0 git |
Not specified |
| CNA |
Linux |
Linux |
affected 4.17.19 4.18 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 4.18 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 4.18 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.148 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.101 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.42 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.6 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc5 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/cfb3ce07b705e486e022a2f2b1242b48f13981ff |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/1e2e2d9806944fe485824d617c8b7c78116c22db |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0f8690e3869109cd5803ccb400889d20a0b54e0e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/9591042533140dfe6608d9344806d567dcd39d02 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5521ae71e32a8069ed4ca6e792179dc57bc43ab2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.