CVE-2025-21635
rds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy
Published:
1/19/2025
Last updated:
10/1/2025
Reserved:
12/29/2024
In the Linux kernel, the following vulnerability has been resolved:
rds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy
As mentioned in a previous commit of this series, using the 'net'
structure via 'current' is not recommended for different reasons:
- Inconsistency: getting info from the reader's/writer's netns vs only
from the opener's netns.
- current->nsproxy can be NULL in some cases, resulting in an 'Oops'
(null-ptr-deref), e.g. when the current task is exiting, as spotted by
syzbot [1] using acct(2).
The per-netns structure can be obtained from the table->data using
container_of(), then the 'net' one can be retrieved from the listen
socket (if available).
CNA assigner:
Linux (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
Requested by:
n/a
Products affected (4)
| Product |
Vendor |
Version |
| Linux |
Linux
|
14.0.0
|
| Linux |
Linux
|
PR-400MI/RT-400MI/RV-440MI firmware version Ver. 07.00.1012 and earlier
|
| Linux |
Linux
|
>= 17.0.0-rc-1, < 17.0.0
|
| Linux |
Linux
|
QCS5430
|