Database/Kernel, userspace & hypervisor
Linux kernel (net/rds): When pinning user pages for a zerocopy RDS send fails, the pages are released but the
Impact
When pinning user pages for a zerocopy RDS send fails, the pages are released but the scatter-list count is left non-zero, so the message purge path walks the stale entries and frees the same pages a second time. A tenant that makes iov_iter_get_pages2() fail on purpose gets a double free of page structures - a strong heap-corruption primitive that can be aimed at memory belonging to other tenants.
Who can reach it
Local and unprivileged: socket(AF_RDS, SOCK_SEQPACKET, 0) - autoloaded via the net-pf-21 alias with no capability check - then sendmsg() with MSG_ZEROCOPY over an iovec crafted so page pinning fails partway (unmapped or unpinnable pages). No RDMA hardware, device node, or capability is needed; the failure is entirely under the tenant's control, which makes it far more attractive than a timing race.
What to do
Boot a kernel carrying the fix commits (resets op_nents on the zerocopy pin failure path). Interim: blacklist the rds module family (install rds /bin/false) or deny socket family 21 in tenant seccomp profiles.
References
Related entries
- Linux kernel (net/rds): A zerocopy RDS send that fails after pinning user pages but before the message reaches theCVE-2026-43502 · Linux kernel (net/rds)High
- Linux kernel (net/rds): Network-namespace teardown frees the per-netns RDS/TCP listen socket before unregistering theCVE-2026-68290 · Linux kernel (net/rds)High
- Linux kernel (net/rds): Bind() on an RDS socket with a scoped IPv6 address looks up the interface under RCU, drops theCVE-2026-74563 · Linux kernel (net/rds)High
- Linux kernel (net/rds): RDS always programs the masked variants of the RDMA atomic opcodes, but the send-completionCVE-2026-52939 · Linux kernel (net/rds)High
- Linux kernel (net/rds): If RDS/IB queue-pair setup fails after the send ring is allocated but before the receive ringCVE-2026-53355 · Linux kernel (net/rds)Critical
- Linux kernel BPF: negative CO-RE accessor index causes an out-of-bounds read and deterministic kernel crashCVE-2026-45839 · Linux kernel BPF verifier (bpf_core_parse_spec CO-RE accessor parsing)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.