Missing Authorization in Linux kernel - CVE-2026-97476
Published: September 24, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive network and socket information.
The vulnerability exists due to improper access control in the RDS_INFO_* getsockopt handlers when querying RDS information from a separate network namespace. A local user can call getsockopt with RDS_INFO_* options to disclose sensitive network and socket information.
Exploitation requires a fresh user namespace and network namespace.