Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation

cve CVE-2018-5333 2 sources, 2 claims · Watch

Metasploit exploit modules writes:
This module attempts to gain root privileges on Linux systems by abusing a NULL pointer dereference in the `rds_atomic_free_op` function in the Reliable Datagram Sockets (RDS) kernel module (rds.ko). Successful exploitation requires the RDS kernel module to be loaded. If the RDS module is not blacklisted (default); then it will be loaded automatically. This exploit supports 64-bit Ubuntu Linux systems, including distributions based on Ubuntu, such as Linux Mint and Zorin OS. Target offsets are available for: … the claim

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBMetasploit
receipt
Source
Exploit-DB
Its words
Metasploit
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2019-9213;CVE-2018-5333",
  "date_added": "2020-01-23",
  "date_published": "2020-01-23",
  "date_updated": "2020-01-23",
  "description": "Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)",
  "file": "exploits/linux/local/47957.rb",
  "id": "47957",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc.rb",
  "tags": "Metasploit Framework (MSF)",
  "type": "local",
  "verified": "1"
}
—
Platform
platform
not compared
Exploit-DBlinux
receipt
Source
Exploit-DB
Its words
linux
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2019-9213;CVE-2018-5333",
  "date_added": "2020-01-23",
  "date_published": "2020-01-23",
  "date_updated": "2020-01-23",
  "description": "Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)",
  "file": "exploits/linux/local/47957.rb",
  "id": "47957",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc.rb",
  "tags": "Metasploit Framework (MSF)",
  "type": "local",
  "verified": "1"
}
—
Platform
platform
not compared
Metasploit exploit modulesLinux
receipt
Source
Metasploit exploit modules
Its words
Linux
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 14:04 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "x64",
  "author": [
    "Mohamed Ghannam",
    "Jann Horn",
    "wbowling",
    "bcoles <bcoles@gmail.com>",
    "nstarke"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "This module attempts to gain root privileges on Linux systems by abusing\n          a NULL pointer dereference in the `rds_atomic_free_op` function in the\n          Reliable Datagram Sockets (RDS) kernel module (rds.ko).\n\n          Successful exploitation requires the RDS kernel module to be loaded.\n          If the RDS module is not blacklisted (default); then it will be loaded\n          automatically.\n\n          This exploit supports 64-bit Ubuntu Linux systems, including distributions\n          based on Ubuntu, such as Linux Mint and Zorin OS.\n\n          Target offsets are available for:\n\n          Ubuntu 16.04 kernels 4.4.0 <= 4.4.0-116-generic; and\n          Ubuntu 16.04 kernels 4.8.0 <= 4.8.0-54-generic.\n\n          This exploit does not bypass SMAP. Bypasses for SMEP and KASLR are included.\n          Failed exploitation may crash the kernel.\n\n          This module has been tested successfully on various 4.4 and 4.8 kernels.",
  "disclosure_date": "2018-11-01",
  "fullname": "exploit/linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:57:34 +0000",
  "name": "Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "crash-os-down"
    ]
  },
  "path": "/modules/exploits/linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc.rb",
  "platform": "Linux",
  "post_auth": false,
  "rank": 400,
  "ref_name": "linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc",
  "references": [
    "CVE-2018-5333",
    "CVE-2019-9213",
    "BID-102510",
    "URL-https://gist.github.com/wbowling/9d32492bd96d9e7c3bf52e23a0ac30a4",
    "URL-https://github.com/0x36/CVE-pocs/blob/master/CVE-2018-5333-rds-nullderef.c",
    "URL-https://bugs.chromium.org/p/project-zero/issues/detail?id=1792&desc=2",
    "URL-https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-5333.html",
    "URL-https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7d11f77f84b27cef452cee332f4e469503084737",
    "URL-https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=15133f6e67d8d646d0744336b4daa3135452cb0d",
    "URL-https://github.com/bcoles/kernel-exploits/blob/master/CVE-2018-5333/cve-2018-5333.c"
  ],
  "rport": null,
  "session_types": [
    "shell",
    "meterpreter"
  ],
  "targets": [
    "Auto"
  ],
  "type": "exploit"
}
—
Rank
rank
Metasploit exploit modules400
Good. A default target, reliable against the common configuration.
receipt
Source
Metasploit exploit modules
Its words
400
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 14:04 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "x64",
  "author": [
    "Mohamed Ghannam",
    "Jann Horn",
    "wbowling",
    "bcoles <bcoles@gmail.com>",
    "nstarke"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "This module attempts to gain root privileges on Linux systems by abusing\n          a NULL pointer dereference in the `rds_atomic_free_op` function in the\n          Reliable Datagram Sockets (RDS) kernel module (rds.ko).\n\n          Successful exploitation requires the RDS kernel module to be loaded.\n          If the RDS module is not blacklisted (default); then it will be loaded\n          automatically.\n\n          This exploit supports 64-bit Ubuntu Linux systems, including distributions\n          based on Ubuntu, such as Linux Mint and Zorin OS.\n\n          Target offsets are available for:\n\n          Ubuntu 16.04 kernels 4.4.0 <= 4.4.0-116-generic; and\n          Ubuntu 16.04 kernels 4.8.0 <= 4.8.0-54-generic.\n\n          This exploit does not bypass SMAP. Bypasses for SMEP and KASLR are included.\n          Failed exploitation may crash the kernel.\n\n          This module has been tested successfully on various 4.4 and 4.8 kernels.",
  "disclosure_date": "2018-11-01",
  "fullname": "exploit/linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:57:34 +0000",
  "name": "Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "crash-os-down"
    ]
  },
  "path": "/modules/exploits/linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc.rb",
  "platform": "Linux",
  "post_auth": false,
  "rank": 400,
  "ref_name": "linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc",
  "references": [
    "CVE-2018-5333",
    "CVE-2019-9213",
    "BID-102510",
    "URL-https://gist.github.com/wbowling/9d32492bd96d9e7c3bf52e23a0ac30a4",
    "URL-https://github.com/0x36/CVE-pocs/blob/master/CVE-2018-5333-rds-nullderef.c",
    "URL-https://bugs.chromium.org/p/project-zero/issues/detail?id=1792&desc=2",
    "URL-https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-5333.html",
    "URL-https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7d11f77f84b27cef452cee332f4e469503084737",
    "URL-https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=15133f6e67d8d646d0744336b4daa3135452cb0d",
    "URL-https://github.com/bcoles/kernel-exploits/blob/master/CVE-2018-5333/cve-2018-5333.c"
  ],
  "rport": null,
  "session_types": [
    "shell",
    "meterpreter"
  ],
  "targets": [
    "Auto"
  ],
  "type": "exploit"
}
—
Type
type
Exploit-DBlocal
receipt
Source
Exploit-DB
Its words
local
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2019-9213;CVE-2018-5333",
  "date_added": "2020-01-23",
  "date_published": "2020-01-23",
  "date_updated": "2020-01-23",
  "description": "Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)",
  "file": "exploits/linux/local/47957.rb",
  "id": "47957",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc.rb",
  "tags": "Metasploit Framework (MSF)",
  "type": "local",
  "verified": "1"
}
—
Verified
verified
Exploit-DBtrue
receipt
Source
Exploit-DB
Its words
1
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2019-9213;CVE-2018-5333",
  "date_added": "2020-01-23",
  "date_published": "2020-01-23",
  "date_updated": "2020-01-23",
  "description": "Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)",
  "file": "exploits/linux/local/47957.rb",
  "id": "47957",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/local/rds_atomic_free_op_null_pointer_deref_priv_esc.rb",
  "tags": "Metasploit Framework (MSF)",
  "type": "local",
  "verified": "1"
}
—

exploit

Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
zetlyn/cve-metasploit · 2018-11-01
platform Linux rank 400 source
Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)
zetlyn/cve-exploitdb · 2020-01-23
author Metasploit platform linux type local verified true source