CVE-2026-97476
In the Linux kernel, the following vulnerability has been resolved:
rds: filter RDS_INFO_* getsockopt by caller's netns
The RDS_INFO_* family of getsockopt(2) options reads several file-scope global lists that are not per-netns:
The handlers do not filter by the caller's network namespace. rds_info_getsockopt() has no netns or capable() check, and rds_create() has no capable() check, so AF_RDS is reachable from an unprivileged user namespace.
Leer descripción completaMostrar menos
As a result, an unprivileged caller in a fresh user_ns plus netns can read the bound address and sock inode of every RDS socket on the host, the peer address of incoming messages on every RDS socket on the host, the peer address and TCP sequence numbers of every rds-tcp connection on the host, and the peer address and RDS sequence numbers of every RDS connection on the host.
The rds-tcp transport is reachable from a non-initial netns (see rds_set_transport()), so a one-shot init_net gate at rds_info_getsockopt() would deny legitimate per-netns visibility to rds-tcp callers. Instead, filter at each handler by comparing the netns of the caller's socket to the netns of the list entry, or to rds_conn_net(conn) for connection paths. Only copy entries whose netns matches the caller. Counters (RDS_INFO_COUNTERS) are aggregate statistics and remain global.
Reproducer (KASAN VM, rds and rds_tcp loaded): an AF_RDS socket binds 127.0.0.1:4242 in init_net as root. A child process enters a fresh user_ns plus netns and opens AF_RDS there, then calls getsockopt(SOL_RDS, RDS_INFO_SOCKETS). Before this change, the child sees the init_net socket. After this change, the child sees zero entries.
Drop the rds_sock_count, rds_tcp_tc_count, and rds6_tcp_tc_count globals. v2 used them for the size precheck and lens->nr; v3 replaced the precheck with a per-ns count from a first pass over the list, so the globals have no remaining readers. The matching increments and decrements in rds_create()/rds_destroy_sock() and rds_tcp_set_callbacks()/rds_tcp_restore_callbacks() go away with them. Reported by the kernel test robot under clang W=1.
Detalles técnicos trazas, registros y código del informe original
rds_sock_info / rds6_sock_info,
rds_sock_inc_info / rds6_sock_inc_info -> rds_sock_list
rds_tcp_tc_info / rds6_tcp_tc_info -> rds_tcp_tc_list
rds_conn_info / rds6_conn_info,
rds_conn_message_info_cmn (for the *_SEND_MESSAGES and
*_RETRANS_MESSAGES variants),
rds_for_each_conn_info (for RDS_INFO_IB_CONNECTIONS)
-> rds_conn_hash[]CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/093f172296d32499ffac7809629b206178776eb6
- https://git.kernel.org/stable/c/64ca5839916176c3451f61a2c7178033423c67d7
- https://git.kernel.org/stable/c/65fae4b42269dbea7e3842ae4dd0786162c6248e
- https://git.kernel.org/stable/c/8b04dda272c30d46834bb03dd2895b08c090483b
- https://git.kernel.org/stable/c/c4081e49ebe0e3160c4b70ec7639494792dee206
- https://git.kernel.org/stable/c/c96a5209dda666004b8ee1ed7f0d493d09a4f200
- https://git.kernel.org/stable/c/f05142d0eeaa6e8227511c88e10a2b8fe7a78fc4
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97476",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4",
"lessThan": "64ca5839916176c3451f61a2c7178033423c67d7",
"versionType": "git"
},
{
"status": "affected",
"version": "639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4",
"lessThan": "8b04dda272c30d46834bb03dd2895b08c090483b",
"versionType": "git"
},
{
"status": "affected",
"version": "639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4",
"lessThan": "f05142d0eeaa6e8227511c88e10a2b8fe7a78fc4",
"versionType": "git"
},
{
"status": "affected",
"version": "639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4",
"lessThan": "65fae4b42269dbea7e3842ae4dd0786162c6248e",
"versionType": "git"
},
{
"status": "affected",
"version": "639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4",
"lessThan": "093f172296d32499ffac7809629b206178776eb6",
"versionType": "git"
},
{
"status": "affected",
"version": "639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4",
"lessThan": "c4081e49ebe0e3160c4b70ec7639494792dee206",
"versionType": "git"
},
{
"status": "affected",
"version": "639b321b4d8f4e412bfbb2a4a19bfebc1e68ace4",
"lessThan": "c96a5209dda666004b8ee1ed7f0d493d09a4f200",
"versionType": "git"
}
],
"programFiles": [
"net/rds/af_rds.c",
"net/rds/connection.c",
"net/rds/tcp.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.30"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.30",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/rds/af_rds.c",
"net/rds/connection.c",
"net/rds/tcp.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T17:17:24.933",
"references": [
{
"url": "https://git.kernel.org/stable/c/093f172296d32499ffac7809629b206178776eb6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/64ca5839916176c3451f61a2c7178033423c67d7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/65fae4b42269dbea7e3842ae4dd0786162c6248e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8b04dda272c30d46834bb03dd2895b08c090483b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c4081e49ebe0e3160c4b70ec7639494792dee206",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c96a5209dda666004b8ee1ed7f0d493d09a4f200",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f05142d0eeaa6e8227511c88e10a2b8fe7a78fc4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrds: filter RDS_INFO_* getsockopt by caller's netns\n\nThe RDS_INFO_* family of getsockopt(2) options reads several\nfile-scope global lists that are not per-netns:\n\n rds_sock_info / rds6_sock_info,\n rds_sock_inc_info / rds6_sock_inc_info -> rds_sock_list\n rds_tcp_tc_info / rds6_tcp_tc_info -> rds_tcp_tc_list\n rds_conn_info / rds6_conn_info,\n rds_conn_message_info_cmn (for the *_SEND_MESSAGES and\n *_RETRANS_MESSAGES variants),\n rds_for_each_conn_info (for RDS_INFO_IB_CONNECTIONS)\n -> rds_conn_hash[]\n\nThe handlers do not filter by the caller's network namespace.\nrds_info_getsockopt() has no netns or capable() check, and\nrds_create() has no capable() check, so AF_RDS is reachable from\nan unprivileged user namespace. As a result, an unprivileged\ncaller in a fresh user_ns plus netns can read the bound address\nand sock inode of every RDS socket on the host, the peer address\nof incoming messages on every RDS socket on the host, the peer\naddress and TCP sequence numbers of every rds-tcp connection on\nthe host, and the peer address and RDS sequence numbers of every\nRDS connection on the host.\n\nThe rds-tcp transport is reachable from a non-initial netns (see\nrds_set_transport()), so a one-shot init_net gate at\nrds_info_getsockopt() would deny legitimate per-netns visibility\nto rds-tcp callers. Instead, filter at each handler by comparing\nthe netns of the caller's socket to the netns of the list entry,\nor to rds_conn_net(conn) for connection paths. Only copy entries\nwhose netns matches the caller. Counters (RDS_INFO_COUNTERS) are\naggregate statistics and remain global.\n\nReproducer (KASAN VM, rds and rds_tcp loaded): an AF_RDS socket\nbinds 127.0.0.1:4242 in init_net as root. A child process enters\na fresh user_ns plus netns and opens AF_RDS there, then calls\ngetsockopt(SOL_RDS, RDS_INFO_SOCKETS). Before this change, the\nchild sees the init_net socket. After this change, the child\nsees zero entries.\n\nDrop the rds_sock_count, rds_tcp_tc_count, and rds6_tcp_tc_count\nglobals. v2 used them for the size precheck and lens->nr; v3\nreplaced the precheck with a per-ns count from a first pass over\nthe list, so the globals have no remaining readers. The matching\nincrements and decrements in rds_create()/rds_destroy_sock() and\nrds_tcp_set_callbacks()/rds_tcp_restore_callbacks() go away with\nthem. Reported by the kernel test robot under clang W=1."
}
],
"lastModified": "2026-10-03T11:17:57.857",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}