CVE-2026-68294
CVE-2026-68294: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.3
High [CVE-2026-68294] restrict socket creation to the initial network namespace
CVE-2026-68294Source published Source updated
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the initial network namespace QRTR keeps its entire port and node state in module-global variables that are not partitioned per network namespace: qrtr_local_nid is a single global node id (always 1) and qrtr_ports is a single global xarray. qrtr_port_lookup() and qrtr_local_enqueue() operate on that global state with no network-namespace check, and qrtr_create() places no restriction on the namespace a socket is created in. As a result an unprivileged process that creates an AF_QIPCRTR socket in a separate network namespace, e.g. via unshare(CLONE_NEWUSER | CLONE_NEWNET), can send QRTR datagrams - including control-plane messages such as QRTR_TYPE_NEW_SERVER - to QRTR sockets owned…
- Affected products in this advisory
- Red Hat Enterprise Linux 10.0 Extended Update Support
- Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
- Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
- Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
7 more entries in the full advisory.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- kernel-0:6.12.0-211.56.1.el10_2
- kernel-0:6.12.0-55.108.1.el10_0
- kernel-rt-0:4.18.0-553.163.1.rt7.504.el8_10
- kernel-0:4.18.0-305.211.1.el8_4
18 more entries in the full advisory.
- Mitigation guidance
- To mitigate this issue, prevent the `qrtr` kernel module from loading. Create a file `/etc/modprobe.d/blacklist-qrtr.conf` with the content `blacklist qrtr`. A system reboot is required for this change to take effect. This may impact functionality that relies on the QRTR inter-process communication mechanism, such as communication with modems or other remote processors.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.