GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel net/rds: teardown samples RDS_IN_XMIT instead of owning it, racing the transmit path into freed ring state

CVSS 8.1CVE-2026-98069Kernel, userspace & hypervisor+1 more CVEscurated

Impact

rds_conn_shutdown() and rds_tcp_reset_callbacks() quiesced the fastpaths by waiting for RDS_IN_XMIT and RDS_RECV_REFILL to be sampled clear, which is not the same as holding them - the sender can re-acquire the bit the instant the wait returns. The state recheck on the sender side is a store-buffering pattern and acquire_in_xmit() is only an acquire, so on weakly ordered CPUs both sides miss each other's write and the transmit path runs while the transport zeroes its rings and rds_send_path_reset() rewrites transmit state underneath it. The reported symptoms are BUG_ON()s, unexpected opcodes and NULL dereferences in the IB send completion handler during failover - a host crash on a node using RDS over InfiniBand. Exposure is narrow: this only matters if the rds and rds_rdma/rds_tcp modules are actually loaded, which most GPU fleets do not do, and the trigger is connection teardown or failover rather than anything a tenant controls. The upstream fix is a two-patch series and the vendor assigned a separate id to each patch; CVE-2026-98070 is the rds_tcp_reset_callbacks() half of the same race and the same remediation.

Who can reach it

No tenant-facing attack path is described. The race opens during RDS connection teardown or failover, including a duelling inbound connection on a path being torn down, on hosts that have the RDS modules loaded.

What to do

Update to a stable kernel carrying both commits in the series and reboot the affected hosts - drain and reboot per node. If RDS is not in use, confirm the rds, rds_tcp and rds_rdma modules are not loaded (and blacklist them) rather than scheduling a maintenance window for this alone.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2026-98070

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.