Database/Kernel, userspace & hypervisor
Linux kernel RDS (rds_find_bound socket lookup ignores network namespace): This is a literal cross-tenant delivery bug.
Impact
This is a literal cross-tenant delivery bug. RDS looks sockets up in one global hash table keyed only on address, port and scope - the network namespace is not part of the key - so a sender in namespace A delivers a message to a socket living in namespace B. Container isolation on Linux is network namespaces; a protocol whose demultiplexing ignores them is not isolating anything. The memory-safety consequence follows: the received message points at a connection owned by namespace A, and when that namespace is torn down the connection is freed while the surviving socket in namespace B still references it.
Who can reach it
Local, unprivileged. A tenant creates a network namespace (or is given one, as every container is), binds an RDS socket on an address that collides with another namespace's, and sends.
What to do
Kernel update making namespace part of the RDS bind lookup. Immediate and effective: blacklist the rds and rds_rdma modules. RDS is rarely used outside specific Oracle database deployments and is almost never required on a GPU cluster, so removing it is cheap and needs no reboot.
References
Related entries
- Linux kernel mlx5_core MACsec offload: Deleting an offloaded MACsec RX secure channel frees the per-SC metadata_dstCVE-2026-72072 · Linux kernel mlx5_core MACsec offloadHigh
- Linux kernel bpf: fork bailout frees an uninitialized task->bpf_storage, causing UAF or hangCVE-2026-72110 · Linux kernel BPF task local storage (copy_process / free_task bailout)High
- Linux kernel mm: DAX hotplug into an early section leaves ZONE_DEVICE tail struct pages uninitializedCVE-2026-72172 · Linux kernel mm/mm_init (ZONE_DEVICE compound_nr_pages on early sections)High
- Linux kernel (arch/x86/kvm/vmx): The nested vTPR versus TPR-threshold consistency check ran only after KVM had alreadyCVE-2026-72287 · Linux kernel (arch/x86/kvm/vmx)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A use-after-free in the amdkfd (KFD compute driverCVE-2026-72449 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel (net/xfrm): Xfrm_selector_match() compared selectors without checking that the selector family matches theCVE-2026-72450 · Linux kernel (net/xfrm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.