PT-2026-104923 · Azure Linux · Kernel
Published
2026-09-24
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
rds: filter RDS INFO * getsockopt by caller's netns
The RDS INFO * family of getsockopt(2) options reads several
file-scope global lists that are not per-netns:
rds sock info / rds6 sock info,
rds sock inc info / rds6 sock inc info -> rds sock list
rds tcp tc info / rds6 tcp tc info -> rds tcp tc list
rds conn info / rds6 conn info,
rds conn message info cmn (for the * SEND MESSAGES and
- RETRANS MESSAGES variants), rds for each conn info (for RDS INFO IB CONNECTIONS) -> rds conn hash[]
The handlers do not filter by the caller's network namespace.
rds info getsockopt() has no netns or capable() check, and
rds create() has no capable() check, so AF RDS is reachable from
an unprivileged user namespace. As a result, an unprivileged
caller in a fresh user ns plus netns can read the bound address
and sock inode of every RDS socket on the host, the peer address
of incoming messages on every RDS socket on the host, the peer
address and TCP sequence numbers of every rds-tcp connection on
the host, and the peer address and RDS sequence numbers of every
RDS connection on the host.
The rds-tcp transport is reachable from a non-initial netns (see
rds set transport()), so a one-shot init net gate at
rds info getsockopt() would deny legitimate per-netns visibility
to rds-tcp callers. Instead, filter at each handler by comparing
the netns of the caller's socket to the netns of the list entry,
or to rds conn net(conn) for connection paths. Only copy entries
whose netns matches the caller. Counters (RDS INFO COUNTERS) are
aggregate statistics and remain global.
Reproducer (KASAN VM, rds and rds tcp loaded): an AF RDS socket
binds 127.0.0.1:4242 in init net as root. A child process enters
a fresh user ns plus netns and opens AF RDS there, then calls
getsockopt(SOL RDS, RDS INFO SOCKETS). Before this change, the
child sees the init net socket. After this change, the child
sees zero entries.
Drop the rds sock count, rds tcp tc count, and rds6 tcp tc count
globals. v2 used them for the size precheck and lens->nr; v3
replaced the precheck with a per-ns count from a first pass over
the list, so the globals have no remaining readers. The matching
increments and decrements in rds create()/rds destroy sock() and
rds tcp set callbacks()/rds tcp restore callbacks() go away with
them. Reported by the kernel test robot under clang W=1.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel