Database/Kernel, userspace & hypervisor
Linux kernel (net/rds): Network-namespace teardown frees the per-netns RDS/TCP listen socket before unregistering the
Impact
Network-namespace teardown frees the per-netns RDS/TCP listen socket before unregistering the matching sysctl table, and the sysctl handler derives its namespace from that socket. A write to the sysctl racing namespace exit dereferences the freed socket - KASAN confirms a slab-use-after-free, giving a tenant that owns a namespace a host-kernel corruption primitive.
Who can reach it
Local, and reachable by a tenant rather than only by host root wherever unprivileged user namespaces are enabled: a container that creates its own user+network namespace holds CAP_NET_ADMIN inside it, so it can write /proc/sys/net/rds/tcp/* and simultaneously tear the namespace down. On hosts with unprivileged userns disabled this needs real root in a netns. The rds_tcp module autoloads from an unprivileged socket(AF_RDS, ...).
What to do
Update to 6.12.101 or later on that branch, or any kernel carrying the fix commits (unregisters the sysctl table before killing the listen socket). Interim: blacklist rds/rds_tcp, or set kernel.unprivileged_userns_clone=0 / user.max_user_namespaces=0 for tenant workloads that do not need namespaces.
References
Related entries
- Linux kernel (net/rds): Bind() on an RDS socket with a scoped IPv6 address looks up the interface under RCU, drops theCVE-2026-74563 · Linux kernel (net/rds)High
- Linux kernel (net/rds): RDS always programs the masked variants of the RDMA atomic opcodes, but the send-completionCVE-2026-52939 · Linux kernel (net/rds)High
- Linux kernel (net/rds): If RDS/IB queue-pair setup fails after the send ring is allocated but before the receive ringCVE-2026-53355 · Linux kernel (net/rds)Critical
- Linux kernel (net/rds): When pinning user pages for a zerocopy RDS send fails, the pages are released but theCVE-2026-43494 · Linux kernel (net/rds)High
- Linux kernel (net/rds): A zerocopy RDS send that fails after pinning user pages but before the message reaches theCVE-2026-43502 · Linux kernel (net/rds)High
- Linux kernel RDS (rds_find_bound socket lookup ignores network namespace): This is a literal cross-tenant delivery bug.CVE-2026-68335 · Linux kernel RDS (rds_find_bound socket lookup ignores network namespace)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.