Database/Kernel, userspace & hypervisor
Linux kernel (net/xfrm, net/key): No memory corruption here, but a clean namespace boundary break. SA migration
Impact
No memory corruption here, but a clean namespace boundary break. SA migration notifications were multicast to the init namespace regardless of which namespace issued them, so a migration triggered inside a tenant namespace is delivered to the host's IKE daemon as if it were the host's own event - carrying an attacker-chosen selector and new endpoint address. A tenant can therefore feed the host key-management daemon a forged MOBIKE-style address update, and in the other direction a tenant's own daemon never sees its migrations, so address updates inside a namespace silently do not work. Both halves mean fabric encryption ends up pointed at an endpoint someone else chose.
Who can reach it
A tenant container with CAP_NET_ADMIN in its own user+network namespace issues XFRM_MSG_MIGRATE (or the PF_KEY equivalent) on its own namespace's socket; the notification is delivered to XFRMNLGRP_MIGRATE and PF_KEY listeners in the init namespace, i.e. to the host's IKE daemon. Exploitability depends on whether that daemon acts on migrate notifications without re-validating the originating namespace - most do not check, because until this fix the notification could only come from init_net. No fabric access needed.
What to do
Boot a kernel carrying the fix commits below (no fixed stable version published). Interim control: do not run a host IKE daemon subscribed to XFRMNLGRP_MIGRATE or PF_KEY BROADCAST_ALL on nodes where tenants hold CAP_NET_ADMIN in their own namespaces, and remove that capability from tenant namespaces.
References
Related entries
- zbus_polkit: caller-supplied UID is silently discarded, leaving polkit authorization open to a PID-reuse raceCVE-2026-78422 · zbus_polkit Rust crate (Subject::new_for_owner UID encoding)High
- OpenZFS: ioctl checks accept unprivileged user-namespace capabilities, granting local pool adminCVE-2026-79619 · OpenZFS on Linux (/dev/zfs ioctl privilege checks vs. unprivileged user namespaces)High
- Linux kernel eBPF: syncookie helpers read sk_protocol on mini-sockets without a fullsock checkCVE-2026-80738 · Linux kernel eBPF (bpf_tcp_gen_syncookie / bpf_tcp_check_syncookie helpers)High
- Xen on AMD - x86 HVM pagetable height update: AMD HVM guest OS users can trigger a data-structure access during aCVE-2019-19577 · Xen on AMD - x86 HVM pagetable height updateHigh
- IBM Spectrum Scale kernel module: An unauthenticated local trigger takes down the Spectrum Scale kernel module and withCVE-2020-4411 · IBM Spectrum Scale kernel moduleHigh
- Xen - x86 IOMMU command timeout detection and handling: Xen's IOMMU command timeout handling is inappropriate, so IOMMUCVE-2021-28692 · Xen - x86 IOMMU command timeout detection and handlingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.