Database/Kernel, userspace & hypervisor
Linux kernel net/rds: a shutdown consuming a racing drop leaves an accepted socket wedged and never torn down
Impact
rds_conn_shutdown() accepted RDS_CONN_ERROR as the starting state of its final transition to RDS_CONN_DOWN, which also consumed the shutdown pass that came with the drop. When rds_tcp_accept_one() is the dropper, it can install a freshly accepted socket while the queued teardown - which sampled t_sock before that socket existed - is still running; the pass that should reap the new socket then finds the path already RDS_CONN_DOWN and does nothing. The socket stays established with its callbacks armed and on rds_tcp_tc_list, the peer sees a connection nothing ever reads, and the path is wedged in RDS_CONN_DOWN until a later event drops it. On a cluster using RDS over TCP for HPC or Oracle-style messaging that is a stalled interconnect path with an ever-growing receive queue and the peer's send path blocked behind it - a hang, not memory corruption. Only affects nodes that actually load and use the rds module.
Who can reach it
Local or on-fabric: triggered by a race between a concurrent connection drop (a FIN on a previous socket processed in softirq, or an administrative reset) and an incoming RDS/TCP accept. No authentication is described; the reproduction needed widened race windows, so hitting it deliberately is not straightforward.
What to do
Update to a stable kernel where the final transition is only DISCONNECTING -> DOWN and the racing-drop case cancels the reconnect timer, clears RDS_RECONNECT_PENDING and returns so the drop's own pass finishes the teardown. Requires a node reboot after drain. If RDS is not needed, blacklisting the rds and rds_tcp modules removes the exposure without a reboot of the fabric stack beyond unloading them.
References
Related entries
- Linux kernel net/rds: a blanket cp_flags store in the connection reset races atomic bitops and discards updatesCVE-2026-98071 · Linux kernel net/rds (rds_conn_path_reset() plain store to cp_flags)Unscored
- Linux kernel net/rds: a missing barrier in release_in_xmit() loses the wake-up and strands the RDS shutdown workerCVE-2026-98072 · Linux kernel net/rds (release_in_xmit() missing barrier before the wake-up check)Unscored
- Linux kernel BPF: a BPF_PSEUDO_FUNC load of the main program is never relocated, leaving a call to a bogus addressCVE-2026-98075 · Linux kernel BPF verifier (BPF_PSEUDO_FUNC reference to the main program)Unscored
- Linux kernel mpt3sas: NUMA_NO_NODE from dev_to_node() causes an out-of-bounds node_to_cpumask_map readCVE-2026-98088 · Linux kernel mpt3sas (_base_assign_reply_queues() NUMA node lookup)Unscored
- Linux kernel mpi3mr: error path in mpi3mr_sas_port_add() leaks a target device referenceCVE-2026-98128 · Linux kernel mpi3mr (target device refcount leak in mpi3mr_sas_port_add())Unscored
- Linux kernel mpi3mr: NULL dereference and sas_port leak when SAS port allocation failsCVE-2026-98129 · Linux kernel mpi3mr (Broadcom tri-mode SAS/SATA/NVMe HBA driver)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.