<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 07:39:12 +0000</lastBuildDate>
    <item>
      <title>CVE-2021-46912 — net: Make tcp_allowed_congestion_control readonly in non-init netns</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2021-46912</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: Make tcp_allowed_congestion_control readonly in non-init netns&lt;/p&gt;
&lt;p&gt;Currently, tcp_allowed_congestion_control is global and writable;
writing to it in any net namespace will leak into all other net
namespaces.&lt;/p&gt;
&lt;p&gt;tcp_available_congestion_control and tcp_allowed_congestion_control are
the only sysctls in ipv4_net_table (the per-netns sysctl table) with a
NULL data pointer; their handlers (proc_tcp_available_congestion_control
and proc_allowed_congestion_control) have no other way of referencing a
struct net. Thus, they operate globally.&lt;/p&gt;
&lt;p&gt;Because ipv4_net_table does not use designated initializers, there is no
easy way to fix up this one &amp;#34;bad&amp;#34; table entry. However, the data pointer
updating logic shouldn&amp;#39;t be applied to NULL pointers anyway, so we
instead force these entries to be read-only.&lt;/p&gt;
&lt;p&gt;These sysctls used to exist in ipv4_table (init-net only), but they were
moved to the per-net ipv4_net_table, presumably without realizing that
tcp_allowed_congestion_control was writable and thus introduced a leak.&lt;/p&gt;
&lt;p&gt;Because the intent of that commit was only to know (i.e. read) &amp;#34;which
congestion algorithms are available or allowed&amp;#34;, this read-only solution
should be sufficient.&lt;/p&gt;
&lt;p&gt;The logic added in recent commit
31c4d2f160eb: (&amp;#34;net: Ensure net namespace isolation of sysctls&amp;#34;)
does not and cannot check for NULL data pointers, because
other table entries (e.g. /proc/sys/net/netfilter/nf_log/) have
.data=NULL but use other m…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: Make tcp_allowed_congestion_control readonly in non-init netns&lt;/p&gt;
&lt;p&gt;Currently, tcp_allowed_congestion_control is global and writable;
writing to it in any net namespace will leak into all other net
namespaces.&lt;/p&gt;
&lt;p&gt;tcp_available_congestion_control and tcp_allowed_congestion_control are
the only sysctls in ipv4_net_table (the per-netns sysctl table) with a
NULL data pointer; their handlers (proc_tcp_available_congestion_control
and proc_allowed_congestion_control) have no other way of referencing a
struct net. Thus, they operate globally.&lt;/p&gt;
&lt;p&gt;Because ipv4_net_table does not use designated initializers, there is no
easy way to fix up this one &amp;#34;bad&amp;#34; table entry. However, the data pointer
updating logic shouldn&amp;#39;t be applied to NULL pointers anyway, so we
instead force these entries to be read-only.&lt;/p&gt;
&lt;p&gt;These sysctls used to exist in ipv4_table (init-net only), but they were
moved to the per-net ipv4_net_table, presumably without realizing that
tcp_allowed_congestion_control was writable and thus introduced a leak.&lt;/p&gt;
&lt;p&gt;Because the intent of that commit was only to know (i.e. read) &amp;#34;which
congestion algorithms are available or allowed&amp;#34;, this read-only solution
should be sufficient.&lt;/p&gt;
&lt;p&gt;The logic added in recent commit
31c4d2f160eb: (&amp;#34;net: Ensure net namespace isolation of sysctls&amp;#34;)
does not and cannot check for NULL data pointers, because
other table entries (e.g. /proc/sys/net/netfilter/nf_log/) have
.data=NULL but use other m…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2021-46912</guid>
    </item>
  </channel>
</rss>
