Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation

zetlyn/cve-metasploit exploit cve CVE-2018-5333 cve CVE-2019-9213 known 2018-11-01

https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc.rb

Properties

platformLinux
receipt
Source
Metasploit exploit modules
Its words
Linux
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 18:04 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "x64",
  "author": [
    "Mohamed Ghannam",
    "Jann Horn",
    "wbowling",
    "bcoles <bcoles@gmail.com>",
    "nstarke"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "This module attempts to gain root privileges on Linux systems by abusing\n          a NULL pointer dereference in the `rds_atomic_free_op` function in the\n          Reliable Datagram Sockets (RDS) kernel module (rds.ko).\n\n          Successful exploitation requires the RDS kernel module to be loaded.\n          If the RDS module is not blacklisted (default); then it will be loaded\n          automatically.\n\n          This exploit supports 64-bit Ubuntu Linux systems, including distributions\n          based on Ubuntu, such as Linux Mint and Zorin OS.\n\n          Target offsets are available for:\n\n          Ubuntu 16.04 kernels 4.4.0 <= 4.4.0-116-generic; and\n          Ubuntu 16.04 kernels 4.8.0 <= 4.8.0-54-generic.\n\n          This exploit does not bypass SMAP. Bypasses for SMEP and KASLR are included.\n          Failed exploitation may crash the kernel.\n\n          This module has been tested successfully on various 4.4 and 4.8 kernels.",
  "disclosure_date": "2018-11-01",
  "fullname": "exploit/linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:57:34 +0000",
  "name": "Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "crash-os-down"
    ]
  },
  "path": "/modules/exploits/linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc.rb",
  "platform": "Linux",
  "post_auth": false,
  "rank": 400,
  "ref_name": "linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc",
  "references": [
    "CVE-2018-5333",
    "CVE-2019-9213",
    "BID-102510",
    "URL-https://gist.github.com/wbowling/9d32492bd96d9e7c3bf52e23a0ac30a4",
    "URL-https://github.com/0x36/CVE-pocs/blob/master/CVE-2018-5333-rds-nullderef.c",
    "URL-https://bugs.chromium.org/p/project-zero/issues/detail?id=1792&desc=2",
    "URL-https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-5333.html",
    "URL-https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7d11f77f84b27cef452cee332f4e469503084737",
    "URL-https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=15133f6e67d8d646d0744336b4daa3135452cb0d",
    "URL-https://github.com/bcoles/kernel-exploits/blob/master/CVE-2018-5333/cve-2018-5333.c"
  ],
  "rport": null,
  "session_types": [
    "shell",
    "meterpreter"
  ],
  "targets": [
    "Auto"
  ],
  "type": "exploit"
}
rank400
Good. A default target, reliable against the common configuration.
receipt
Source
Metasploit exploit modules
Its words
400
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 18:04 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "x64",
  "author": [
    "Mohamed Ghannam",
    "Jann Horn",
    "wbowling",
    "bcoles <bcoles@gmail.com>",
    "nstarke"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "This module attempts to gain root privileges on Linux systems by abusing\n          a NULL pointer dereference in the `rds_atomic_free_op` function in the\n          Reliable Datagram Sockets (RDS) kernel module (rds.ko).\n\n          Successful exploitation requires the RDS kernel module to be loaded.\n          If the RDS module is not blacklisted (default); then it will be loaded\n          automatically.\n\n          This exploit supports 64-bit Ubuntu Linux systems, including distributions\n          based on Ubuntu, such as Linux Mint and Zorin OS.\n\n          Target offsets are available for:\n\n          Ubuntu 16.04 kernels 4.4.0 <= 4.4.0-116-generic; and\n          Ubuntu 16.04 kernels 4.8.0 <= 4.8.0-54-generic.\n\n          This exploit does not bypass SMAP. Bypasses for SMEP and KASLR are included.\n          Failed exploitation may crash the kernel.\n\n          This module has been tested successfully on various 4.4 and 4.8 kernels.",
  "disclosure_date": "2018-11-01",
  "fullname": "exploit/linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:57:34 +0000",
  "name": "Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "crash-os-down"
    ]
  },
  "path": "/modules/exploits/linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc.rb",
  "platform": "Linux",
  "post_auth": false,
  "rank": 400,
  "ref_name": "linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc",
  "references": [
    "CVE-2018-5333",
    "CVE-2019-9213",
    "BID-102510",
    "URL-https://gist.github.com/wbowling/9d32492bd96d9e7c3bf52e23a0ac30a4",
    "URL-https://github.com/0x36/CVE-pocs/blob/master/CVE-2018-5333-rds-nullderef.c",
    "URL-https://bugs.chromium.org/p/project-zero/issues/detail?id=1792&desc=2",
    "URL-https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-5333.html",
    "URL-https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7d11f77f84b27cef452cee332f4e469503084737",
    "URL-https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=15133f6e67d8d646d0744336b4daa3135452cb0d",
    "URL-https://github.com/bcoles/kernel-exploits/blob/master/CVE-2018-5333/cve-2018-5333.c"
  ],
  "rport": null,
  "session_types": [
    "shell",
    "meterpreter"
  ],
  "targets": [
    "Auto"
  ],
  "type": "exploit"
}

Text

This module attempts to gain root privileges on Linux systems by abusing a NULL pointer dereference in the `rds_atomic_free_op` function in the Reliable Datagram Sockets (RDS) kernel module (rds.ko). Successful exploitation requires the RDS kernel module to be loaded. If the RDS module is not blacklisted (default); then it will be loaded automatically. This exploit supports 64-bit Ubuntu Linux systems, including distributions based on Ubuntu, such as Linux Mint and Zorin OS. Target offsets are available for: Ubuntu 16.04 kernels 4.4.0 <= 4.4.0-116-generic; and Ubuntu 16.04 kernels 4.8.0 <= 4.8.0-54-generic. This exploit does not bypass SMAP. Bypasses for SMEP and KASLR are included. Failed exploitation may crash the kernel. This module has been tested successfully on various 4.4 and 4.8 kernels.