PT-2026-104923 · Azure Linux · Kernel

Publicado

2026-09-24

·

Atualizado

2026-09-24

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
rds: filter RDS INFO * getsockopt by caller's netns
The RDS INFO * family of getsockopt(2) options reads several file-scope global lists that are not per-netns:
rds sock info / rds6 sock info, rds sock inc info / rds6 sock inc info -> rds sock list rds tcp tc info / rds6 tcp tc info -> rds tcp tc list rds conn info / rds6 conn info, rds conn message info cmn (for the * SEND MESSAGES and
  • RETRANS MESSAGES variants), rds for each conn info (for RDS INFO IB CONNECTIONS) -> rds conn hash[]
The handlers do not filter by the caller's network namespace. rds info getsockopt() has no netns or capable() check, and rds create() has no capable() check, so AF RDS is reachable from an unprivileged user namespace. As a result, an unprivileged caller in a fresh user ns plus netns can read the bound address and sock inode of every RDS socket on the host, the peer address of incoming messages on every RDS socket on the host, the peer address and TCP sequence numbers of every rds-tcp connection on the host, and the peer address and RDS sequence numbers of every RDS connection on the host.
The rds-tcp transport is reachable from a non-initial netns (see rds set transport()), so a one-shot init net gate at rds info getsockopt() would deny legitimate per-netns visibility to rds-tcp callers. Instead, filter at each handler by comparing the netns of the caller's socket to the netns of the list entry, or to rds conn net(conn) for connection paths. Only copy entries whose netns matches the caller. Counters (RDS INFO COUNTERS) are aggregate statistics and remain global.
Reproducer (KASAN VM, rds and rds tcp loaded): an AF RDS socket binds 127.0.0.1:4242 in init net as root. A child process enters a fresh user ns plus netns and opens AF RDS there, then calls getsockopt(SOL RDS, RDS INFO SOCKETS). Before this change, the child sees the init net socket. After this change, the child sees zero entries.
Drop the rds sock count, rds tcp tc count, and rds6 tcp tc count globals. v2 used them for the size precheck and lens->nr; v3 replaced the precheck with a per-ns count from a first pass over the list, so the globals have no remaining readers. The matching increments and decrements in rds create()/rds destroy sock() and rds tcp set callbacks()/rds tcp restore callbacks() go away with them. Reported by the kernel test robot under clang W=1.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

AZL-103778

Produtos afetados

Kernel