Database/Kernel, userspace & hypervisor
Linux kernel RDS: congestion map scatterlist overruns on >8K page sizes, corrupting the RDS-TCP stream
Impact
rds_message_map_pages() set every scatterlist entry to PAGE_SIZE even when the mapped object ended mid-page. The RDS congestion map is a fixed 8192 bytes, so on a kernel with PAGE_SIZE larger than 8192 the scatterlist described bytes past the end of the map. RDS-TCP then transmitted those bytes as part of the stream, where the peer parsed them as the next RDS message header - stream corruption, plus leakage of whatever adjacent kernel page content followed the map. This matters on GPU nodes specifically because the exposure is page-size dependent: arm64 fleets built with 16K or 64K pages (the configuration common on Grace-class and other arm64 accelerator hosts) are affected, while 4K-page x86 nodes are not affected at all. The commit notes the RDS selftest previously hung on 16K pages.
Who can reach it
Requires RDS to be in use (the rds and rds_tcp modules loaded) on a kernel built with PAGE_SIZE > 8192. The corrupted bytes go to the RDS peer, so the party who observes the malformed stream and the leaked adjacent bytes is whoever is on the other end of an RDS-TCP connection. Not reachable on 4K-page hosts.
What to do
Update to a stable kernel carrying the fix that limits the final scatterlist entry to the bytes remaining, then drain and reboot the node. Interim mitigation if RDS is not actually needed: do not load the rds/rds_tcp modules, or blacklist them, which removes the exposure without a reboot. No fixed distro version is named in the record.
References
Related entries
- Linux kernel ice: missing xa_destroy leaks xarray memory on every HW re-initCVE-2026-97979 · Linux kernel ice driver (sched_node_ids xarray teardown)Unscored
- Linux kernel vhost-vdpa: failed eventfd install leaves an ERR_PTR reachable by the config callbackCVE-2026-97993 · Linux kernel vhost-vdpa (ERR_PTR installed in v->config_ctx by VHOST_VDPA_SET_CONFIG_CALL)Unscored
- Linux kernel vhost-vdpa: queue size is not checked against the device maximum, giving an out-of-bounds descriptor readCVE-2026-97994 · Linux kernel vhost-vdpa (VHOST_SET_VRING_NUM validation)Unscored
- Linux kernel BPF verifier (bpf_loop nr_loops argument type): bpf_loop() declared nr_loops as ARG_ANYTHING, so aCVE-2026-98007 · Linux kernel BPF verifier (bpf_loop nr_loops argument type)Unscored
- Linux kernel BPF: bpf_btf_find_by_name_kind() can sleep in softirq context and install an fd into the interrupted taskCVE-2026-98046 · Linux kernel BPF helper bpf_btf_find_by_name_kind() (missing sleepable annotation)Unscored
- Linux kernel BPF: bpf_snprintf_btf() on a BTF_KIND_VAR from base BTF NULL-derefs in btf_var_show()CVE-2026-98063 · Linux kernel BPF BTF display (btf_var_show() unguarded resolved_ids deref)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.