High [CVE-2026-68294] restrict socket creation to the initial network namespace
This high-severity Red Hat Linux advisory covers CVE-2026-68294 affecting Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the initial network namespace QRTR keeps its entire port and node state in module-global variables that are not partitioned per network namespace: qrtr_local_nid is a single global node id (always 1) and qrtr_ports is a single global xarray. qrtr_port_lookup() and qrtr_local_enqueue() operate on that global state with no network-namespace check, and qrtr_create() places no restriction on the namespace a socket is created in.
As a result an unprivileged process that creates an AF_QIPCRTR socket in a separate network namespace, e.g. via unshare(CLONE_NEWUSER | CLONE_NEWNET), can send QRTR datagrams - including control-plane messages such as QRTR_TYPE_NEW_SERVER - to QRTR sockets owned by another namespace, and vice versa.
The receiving socket sees such a message as coming from node id 1, indistinguishable from a legitimate local client, breaking the isolation that network namespaces are expected to provide.
QRTR is a transport to global hardware endpoints (the modem and other remote processors) and has no per-namespace semantics; its in-kernel name service already creates its socket in init_net only. Confine the socket family to the initial network namespace, as other non-namespace-aware socket families do (see llc_ui_create() and the ieee802154 socket code).
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 56 minutes ago·verify at source
- kernel-0:6.12.0-211.56.1.el10_2
- kernel-0:6.12.0-55.108.1.el10_0
- kernel-rt-0:4.18.0-553.163.1.rt7.504.el8_10
- kernel-0:4.18.0-305.211.1.el8_4
- kernel-0:4.18.0-372.220.1.el8_6
- kernel-0:4.18.0-477.172.1.el8_8
- kernel-0:5.14.0-687.48.1.el9_8
- kernel-0:5.14.0-284.195.1.el9_2
- kernel-rt-0:5.14.0-284.195.1.rt14.480.el9_2
- kernel-0:5.14.0-427.153.1.el9_4
- kernel-0:5.14.0-570.146.1.el9_6
- RHSA-2026:68507
- RHSA-2026:75560
- RHSA-2026:67469
- RHSA-2026:77217
- RHSA-2026:77216
- RHSA-2026:77301
- RHSA-2026:67470
- RHSA-2026:77215
- RHSA-2026:77214
- RHSA-2026:73645
- RHSA-2026:74174
Official advisory · high-confidence parse· fetched 56 minutes ago·verify at source
Mitigation checklist
- To mitigate this issue, prevent the `qrtr` kernel module from loading. Create a file `/etc/modprobe.d/blacklist-qrtr.conf` with the content `blacklist qrtr`. A system reboot is required for this change to take effect. This may impact functionality that relies on the QRTR inter-process communication mechanism, such as communication with modems or other remote processors.
Official advisory · high-confidence parse· fetched 56 minutes ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.