GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel RDS: congestion map scatterlist overruns on >8K page sizes, corrupting the RDS-TCP stream

UnscoredCVE-2026-97954Kernel, userspace & hypervisorcurated

Impact

rds_message_map_pages() set every scatterlist entry to PAGE_SIZE even when the mapped object ended mid-page. The RDS congestion map is a fixed 8192 bytes, so on a kernel with PAGE_SIZE larger than 8192 the scatterlist described bytes past the end of the map. RDS-TCP then transmitted those bytes as part of the stream, where the peer parsed them as the next RDS message header - stream corruption, plus leakage of whatever adjacent kernel page content followed the map. This matters on GPU nodes specifically because the exposure is page-size dependent: arm64 fleets built with 16K or 64K pages (the configuration common on Grace-class and other arm64 accelerator hosts) are affected, while 4K-page x86 nodes are not affected at all. The commit notes the RDS selftest previously hung on 16K pages.

Who can reach it

Requires RDS to be in use (the rds and rds_tcp modules loaded) on a kernel built with PAGE_SIZE > 8192. The corrupted bytes go to the RDS peer, so the party who observes the malformed stream and the leaked adjacent bytes is whoever is on the other end of an RDS-TCP connection. Not reachable on 4K-page hosts.

What to do

Update to a stable kernel carrying the fix that limits the final scatterlist entry to the bytes remaining, then drain and reboot the node. Interim mitigation if RDS is not actually needed: do not load the rds/rds_tcp modules, or blacklist them, which removes the exposure without a reboot. No fixed distro version is named in the record.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.