Database/Kernel, userspace & hypervisor
Linux kernel net/rds: teardown samples RDS_IN_XMIT instead of owning it, racing the transmit path into freed ring state
Impact
rds_conn_shutdown() and rds_tcp_reset_callbacks() quiesced the fastpaths by waiting for RDS_IN_XMIT and RDS_RECV_REFILL to be sampled clear, which is not the same as holding them - the sender can re-acquire the bit the instant the wait returns. The state recheck on the sender side is a store-buffering pattern and acquire_in_xmit() is only an acquire, so on weakly ordered CPUs both sides miss each other's write and the transmit path runs while the transport zeroes its rings and rds_send_path_reset() rewrites transmit state underneath it. The reported symptoms are BUG_ON()s, unexpected opcodes and NULL dereferences in the IB send completion handler during failover - a host crash on a node using RDS over InfiniBand. Exposure is narrow: this only matters if the rds and rds_rdma/rds_tcp modules are actually loaded, which most GPU fleets do not do, and the trigger is connection teardown or failover rather than anything a tenant controls. The upstream fix is a two-patch series and the vendor assigned a separate id to each patch; CVE-2026-98070 is the rds_tcp_reset_callbacks() half of the same race and the same remediation.
Who can reach it
No tenant-facing attack path is described. The race opens during RDS connection teardown or failover, including a duelling inbound connection on a path being torn down, on hosts that have the RDS modules loaded.
What to do
Update to a stable kernel carrying both commits in the series and reboot the affected hosts - drain and reboot per node. If RDS is not in use, confirm the rds, rds_tcp and rds_rdma modules are not loaded (and blacklist them) rather than scheduling a maintenance window for this alone.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- Linux kernel (virt/kvm): The dirty-ring reset path bounds-checks an offset with unchecked 64-bit arithmetic, so aCVE-2026-52969 · Linux kernel (virt/kvm)High
- Linux kernel (arch/x86/kvm/svm): VMLOAD/VMSAVE executed by an L2 guest and not intercepted by L1 were emulated againstCVE-2026-43133 · Linux kernel (arch/x86/kvm/svm)High
- util-linux nsenter: --join-cgroup leaks a root-opened cgroup.procs fd into the target containerCVE-2026-78408 · util-linux nsenter (--join-cgroup descriptor leak across execve)High
- Linux kernel KVM/arm64: guest-controlled TLBI Range can overflow the hypervisor's range computationCVE-2026-89911 · Linux kernel KVM arm64 (TLBI by Range)High
- Linux kernel RDS (Reliable Datagram Sockets) net/rds/page.c - rds_page_copy_user: Straight local-to-root. RDS - theCVE-2010-3904 · Linux kernel RDS (Reliable Datagram Sockets) net/rds/page.c - rds_page_copy_userHigh
- Linux kernel KVM device assignment IOMMU path virt/kvm/iommu.c - kvm_iommu_map_pages: When an IOMMU mapping failsCVE-2014-3601 · Linux kernel KVM device assignment IOMMU path virt/kvm/iommu.c - kvm_iommu_map_pagesHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.