Database/Kernel, userspace & hypervisor
Linux kernel net/rds: unprivileged container reads every RDS socket and connection on the host
Impact
The RDS_INFO_* getsockopt handlers walked file-scope global lists without filtering by the caller's network namespace, and neither rds_create() nor rds_info_getsockopt() required any capability. A process in a fresh user namespace plus network namespace - which is what a container is - could therefore read the bound address and socket inode of every RDS socket on the host, the peer addresses of incoming messages, and the peer addresses plus TCP and RDS sequence numbers of every RDS connection. On a multi-tenant GPU node that is a namespace-crossing information leak about the host's storage and interconnect traffic; the sequence numbers in particular are material for anyone trying to interfere with an rds-tcp connection. Read-only: no write, no corruption, no code execution. Exposure requires the rds and rds_tcp modules to be loaded, which most GPU nodes do not do unless they use RDS - blacklisting them removes the issue entirely.
Who can reach it
Any local unprivileged user or container process that can create an AF_RDS socket, on a host where the rds module is loaded. No capabilities and no authentication beyond local access are required.
What to do
Take the stable kernel fix that filters each handler by the caller's netns and reboot the node - a drain-and-reboot per node on the usual kernel-update cadence. Where the kernel update cannot be scheduled, confirm whether RDS is actually in use; if it is not, blacklist the rds and rds_tcp modules, which closes the path without a reboot window of its own.
References
Related entries
- Linux kernel net/rds: RDS-over-IB shutdown sleeps in a shared worker and hangs fabric teardownCVE-2026-97491 · Linux kernel net/rds over InfiniBand (rds_ib_conn_path_shutdown sleeping in the shutdown worker)Unscored
- Linux PCI sysfs: BAR resize via resourceN_resize had no CAP_SYS_ADMIN checkCVE-2026-97505 · Linux kernel PCI sysfs (resourceN_resize, __resource_resize_store)Unscored
- Linux qla2xxx: double free and NULL dma_pool use when adapter memory allocation fails at probeCVE-2026-97532 · Linux kernel scsi qla2xxx (qla2x00_mem_alloc error path, dangling pointers)Unscored
- Linux qla2xxx: NULL dma_free and mismatched bitmap locking in multiqueue queue teardownCVE-2026-97537 · Linux kernel scsi qla2xxx (multiqueue req/rsp queue teardown, qid bitmap locking)Unscored
- Linux LIO iSCSI target: LUN_RESET on a WRITE_PENDING command deadlocks the target worker threadCVE-2026-97951 · Linux kernel SCSI target iSCSI frontend (aborted WRITE_PENDING dataout handling)Unscored
- Linux cgroup: task iterator can resurrect a zero-refcount dying task, giving a use-after-freeCVE-2026-98163 · Linux kernel cgroup task iterator (css_task_iter_next over dying_tasks)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.