Database/Kernel, userspace & hypervisor
Linux kernel (net/rds): RDS always programs the masked variants of the RDMA atomic opcodes, but the send-completion
Impact
RDS always programs the masked variants of the RDMA atomic opcodes, but the send-completion path only recognises the unmasked ones, so every atomic operation completes with a NULL message pointer that is then dereferenced. A tenant sending one atomic control message over an RDS/IB connection panics the node from softirq - the commit states plainly that an unprivileged AF_RDS sendmsg() triggers it with no extra setup on mlx4/mlx5.
Who can reach it
Local and unprivileged, single syscall: socket(AF_RDS, SOCK_SEQPACKET, 0) - which autoloads the rds and rds_rdma modules through the net-pf-21 alias with no capability check - then sendmsg() with an RDS atomic cmsg over an active RDS/IB connection. Requires an RDMA device the tenant's traffic can use, which is the normal case on a GPU node, and native masked-atomic support (mlx4/mlx5). The fault is in the completion tasklet, so it is a fatal exception in interrupt context: the whole node goes down.
What to do
Boot a kernel carrying the fix commits (handles the masked atomic opcodes in the completion unmap path). Interim: blacklist the rds, rds_rdma and rds_tcp modules (install rds /bin/false) or deny socket family 21 in tenant seccomp profiles - RDS is almost never intentionally used on a GPU cluster and is a good candidate for blanket removal.
References
Related entries
- Linux kernel (net/rds): If RDS/IB queue-pair setup fails after the send ring is allocated but before the receive ringCVE-2026-53355 · Linux kernel (net/rds)Critical
- Linux kernel (net/rds): When pinning user pages for a zerocopy RDS send fails, the pages are released but theCVE-2026-43494 · Linux kernel (net/rds)High
- Linux kernel (net/rds): A zerocopy RDS send that fails after pinning user pages but before the message reaches theCVE-2026-43502 · Linux kernel (net/rds)High
- Linux kernel (net/rds): Network-namespace teardown frees the per-netns RDS/TCP listen socket before unregistering theCVE-2026-68290 · Linux kernel (net/rds)High
- Linux kernel (net/rds): Bind() on an RDS socket with a scoped IPv6 address looks up the interface under RCU, drops theCVE-2026-74563 · Linux kernel (net/rds)High
- Linux kernel (drivers/pci): An SR-IOV device that stops answering config reads makes the VF Resizable BAR restore pathCVE-2026-64460 · Linux kernel (drivers/pci)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.