CVE-2026-68294: net: qrtr: restrict socket creation to the initial network namespace

Published Aug 10, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: qrtr: restrict socket creation to the initial network namespace

QRTR keeps its entire port and node state in module-global variables that are not partitioned per network namespace: qrtrlocalnid is a single global node id (always 1) and qrtrports is a single global xarray. qrtrportlookup() and qrtrlocalenqueue() operate on that global state with no network-namespace check, and qrtrcreate() places no restriction on the namespace a socket is created in.

As a result an unprivileged process that creates an AFQIPCRTR socket in a separate network namespace, e.g. via unshare(CLONENEWUSER | CLONENEWNET), can send QRTR datagrams - including control-plane messages such as QRTRTYPENEWSERVER - to QRTR sockets owned by another namespace, and vice versa. The receiving socket sees such a message as coming from node id 1, indistinguishable from a legitimate local client, breaking the isolation that network namespaces are expected to provide.

QRTR is a transport to global hardware endpoints (the modem and other remote processors) and has no per-namespace semantics; its in-kernel name service already creates its socket in initnet only. Confine the socket family to the initial network namespace, as other non-namespace-aware socket families do (see llcuicreate() and the ieee802154 socket code).

Affected Software

1 affected component
Linux Kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Apply the fix described as "net: qrtr: restrict socket creation to the initial network namespace" so that QRTR sockets are created only in init_net, preventing socket/node/port global state from being shared across network namespaces.

    Linux kernel (net: qrtr) Restrict socket creation to initial network namespace (init_net) = enabled

Event History

Aug 10, 2026
CVE Published
via MITRE·12:02 PM
Data Sourced
via MITRE·12:02 PM
Description
Data Sourced
via NVD·01:20 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2026-68294?

CVE-2026-68294 is a vulnerability in the Linux kernel that allows unrestricted socket creation in the QRTR protocol across network namespaces.

2

What is the severity of CVE-2026-68294?

The severity of CVE-2026-68294 has been rated at 47, indicating a significant risk to system security.

3

How do I fix CVE-2026-68294?

To fix CVE-2026-68294, you should update the Linux kernel to a version where this vulnerability has been addressed.

4

What systems are affected by CVE-2026-68294?

CVE-2026-68294 affects systems running vulnerable versions of the Linux kernel that utilize the QRTR protocol.

5

Is there a workaround for CVE-2026-68294?

Currently, there are no known workarounds for CVE-2026-68294, so updating the kernel is the recommended action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203