CVE-2025-21635

rds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy

References

Notes

 carnil> Introduced in c6a58ffed536 ("RDS: TCP: Add sysctl tunables for sndbuf/rcvbuf on
 carnil> rds-tcp socket"). Vulnerable versions: 4.6-rc1.

Bugs

Status

Branch Status
upstream released (6.13-rc7) [7f5611cbc4871c7fb1ad36c2e5a9edad63dca95c]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.12-upstream-stable released (6.12.10) [de8d6de0ee27be4b2b1e5b06f04aeacbabbba492]
6.6-upstream-stable needed
6.1-upstream-stable needed
5.10-upstream-stable needed
sid released (6.12.10-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security needed
5.10-bullseye-security needed