Database/Kernel, userspace & hypervisor
Linux kernel RDS connection info (uninitialised per-item buffer copied to userspace): The connection-info walkers hand
Impact
The connection-info walkers hand a per-item stack buffer to a visitor and then copy the full declared item length back to userspace regardless of how much the visitor filled in. When a connection is not in the UP state the IB visitors write only a subset - several u32 fields and an alignment hole are left holding whatever was on the kernel stack - and all of it is copied out. Any unprivileged process that can query RDS info harvests kernel stack bytes, which is the standard first step for defeating KASLR before using a corruption bug.
Who can reach it
Local, unprivileged. Query RDS connection info while at least one connection is not in the UP state - trivially arranged by the querying tenant.
What to do
Kernel update zeroing the item buffer before each visitor call. Blacklisting rds removes the surface immediately.
References
Related entries
- Linux drm/xe GPU kernel driver (suspend/shutdown without display): The xe driver oopses on suspend or shutdownCVE-2026-53142 · Linux drm/xe GPU kernel driver (suspend/shutdown without display)Medium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Missing or insufficient validation of user-suppliedCVE-2026-53144 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
- Linux kernel (drivers/iommu): The reset-completion path re-attaches an IOMMU group's domain without checking that theCVE-2026-53280 · Linux kernel (drivers/iommu)Medium
- Linux KVM - dirty-page tracking without a vCPU on a dying VM: KVM warned (and on panic_on_warn hosts, panicked)CVE-2026-53345 · Linux KVM - dirty-page tracking without a vCPU on a dying VMMedium
- Linux kernel (drivers/iommu/intel): VT-d accepted a PASID attachment to a nested domain whose parent has dirty trackingCVE-2026-53372 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Missing or insufficient validation of user-suppliedCVE-2026-53376 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.