SB20260812199 - Use-after-free in Linux kernel rds
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-68335)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger a use-after-free and potentially execute arbitrary code.
The vulnerability exists due to use-after-free in the RDS receive path when delivering an incoming message across network namespace boundaries. A local user can create network namespaces and send a crafted message to trigger a dangling connection reference and potentially execute arbitrary code.
The issue is reachable from unprivileged user namespaces using CLONE_NEWUSER and CLONE_NEWNET.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0f8690e3869109cd5803ccb400889d20a0b54e0e
- https://git.kernel.org/stable/c/1e2e2d9806944fe485824d617c8b7c78116c22db
- https://git.kernel.org/stable/c/5521ae71e32a8069ed4ca6e792179dc57bc43ab2
- https://git.kernel.org/stable/c/9591042533140dfe6608d9344806d567dcd39d02
- https://git.kernel.org/stable/c/cfb3ce07b705e486e022a2f2b1242b48f13981ff