Database/Kernel, userspace & hypervisor
Linux kernel (net/rds): A zerocopy RDS send that fails after pinning user pages but before the message reaches the
Impact
A zerocopy RDS send that fails after pinning user pages but before the message reaches the socket queue is cleaned up as if it owned ordinary payload pages, because the purge path infers zerocopy ownership from the socket pointer rather than from the notifier. The pinned-page accounting and the page references are then handled wrongly - the tenant controls when the failure happens, so it controls which pages are mis-released.
Who can reach it
Local and unprivileged: an AF_RDS socket (family 21 autoloads on socket() with no capability check) doing a MSG_ZEROCOPY sendmsg that fails early - before the message is attached to the socket. No RDMA device or privileged access is required, and the failure timing is attacker-chosen rather than racy.
What to do
Boot a kernel carrying the fix commits (uses op_mmp_znotifier as the cleanup discriminator in rds_message_purge). Interim: blacklist rds/rds_rdma/rds_tcp or deny socket family 21 to tenants.
References
Related entries
- Linux kernel (net/rds): Network-namespace teardown frees the per-netns RDS/TCP listen socket before unregistering theCVE-2026-68290 · Linux kernel (net/rds)High
- Linux kernel (net/rds): Bind() on an RDS socket with a scoped IPv6 address looks up the interface under RCU, drops theCVE-2026-74563 · Linux kernel (net/rds)High
- Linux kernel (net/rds): RDS always programs the masked variants of the RDMA atomic opcodes, but the send-completionCVE-2026-52939 · Linux kernel (net/rds)High
- Linux kernel (net/rds): If RDS/IB queue-pair setup fails after the send ring is allocated but before the receive ringCVE-2026-53355 · Linux kernel (net/rds)Critical
- Linux kernel (net/rds): When pinning user pages for a zerocopy RDS send fails, the pages are released but theCVE-2026-43494 · Linux kernel (net/rds)High
- Linux kernel BPF: negative CO-RE accessor index causes an out-of-bounds read and deterministic kernel crashCVE-2026-45839 · Linux kernel BPF verifier (bpf_core_parse_spec CO-RE accessor parsing)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.