Database/Kernel, userspace & hypervisor
Linux kernel (net/rds): If RDS/IB queue-pair setup fails after the send ring is allocated but before the receive ring
Impact
If RDS/IB queue-pair setup fails after the send ring is allocated but before the receive ring is, the unwind frees the send ring without clearing the pointer. The teardown logic uses NULL to decide what it still owns, so a later shutdown pass frees the same ring again - a double free / use-after-free of RDMA send state reachable by whoever can make connection setup fail partway.
Who can reach it
Driven from the fabric: RDS/IB connection setup runs from the RDMA CM event handler when a peer connects, and the failure window is a partial setup (resource exhaustion, device limits, a peer that aborts mid-setup), followed by the normal shutdown path. A tenant can also drive repeated RDS connection attempts locally - socket(AF_RDS, ...) is unprivileged and autoloads rds/rds_rdma via the net-pf-21 alias. Requires the RDS RDMA transport in use over an IB/RoCE device.
What to do
Boot a kernel carrying the fix commits (clears i_sends after vfree in the setup unwind). Interim: blacklist rds and rds_rdma, or deny socket family 21 to tenants; RDS over IB is rarely a deliberate dependency on an AI cluster.
References
Related entries
- Linux kernel (net/rds): When pinning user pages for a zerocopy RDS send fails, the pages are released but theCVE-2026-43494 · Linux kernel (net/rds)High
- Linux kernel (net/rds): A zerocopy RDS send that fails after pinning user pages but before the message reaches theCVE-2026-43502 · Linux kernel (net/rds)High
- Linux kernel (net/rds): Network-namespace teardown frees the per-netns RDS/TCP listen socket before unregistering theCVE-2026-68290 · Linux kernel (net/rds)High
- Linux kernel (net/rds): Bind() on an RDS socket with a scoped IPv6 address looks up the interface under RCU, drops theCVE-2026-74563 · Linux kernel (net/rds)High
- Linux kernel (net/rds): RDS always programs the masked variants of the RDMA atomic opcodes, but the send-completionCVE-2026-52939 · Linux kernel (net/rds)High
- Linux kernel (net/xfrm): IPTFS fragment consumption loses the shared-page marker, so ESP concludes the payload pagesCVE-2026-53363 · Linux kernel (net/xfrm)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.