Database/Kernel, userspace & hypervisor
Linux kernel net/rds: a blanket cp_flags store in the connection reset races atomic bitops and discards updates
Impact
rds_conn_path_reset() wiped the whole flag word with a plain cp->cp_flags = 0 store while every other accessor uses atomic bitops, and some of those run concurrently with the reset - RDS_LL_SEND_FULL is set from rds_send_xmit() and cleared from transport completion paths, neither of which excludes the shutdown worker. A plain store racing an atomic read-modify-write on the same word is a data race, and the losing side's update is silently dropped, leaving flow-control state on an RDS path inconsistent after a reset. On a fabric that carries cluster messaging this reads as a stuck or mis-flow-controlled connection rather than a memory-safety problem. The fix also matters structurally: later patches turn RDS_IN_XMIT and RDS_RECV_REFILL into bit locks held across teardown, and a blanket store mid-teardown would destroy that lock ownership. Only affects nodes that load the rds module.
Who can reach it
Local/on-fabric race, not a directed attack: requires a connection reset in the shutdown worker concurrent with send or completion processing on the same RDS path. No authentication element is described in the record.
What to do
Update to a stable kernel where the reset clears only the two bits it owns with atomic ops instead of storing zero over the word. Requires a node reboot after drain. Where RDS is not in use, unloading or blacklisting the rds modules removes the exposure.
References
Related entries
- Linux kernel net/rds: a missing barrier in release_in_xmit() loses the wake-up and strands the RDS shutdown workerCVE-2026-98072 · Linux kernel net/rds (release_in_xmit() missing barrier before the wake-up check)Unscored
- Linux kernel BPF: a BPF_PSEUDO_FUNC load of the main program is never relocated, leaving a call to a bogus addressCVE-2026-98075 · Linux kernel BPF verifier (BPF_PSEUDO_FUNC reference to the main program)Unscored
- Linux kernel mpt3sas: NUMA_NO_NODE from dev_to_node() causes an out-of-bounds node_to_cpumask_map readCVE-2026-98088 · Linux kernel mpt3sas (_base_assign_reply_queues() NUMA node lookup)Unscored
- Linux kernel mpi3mr: error path in mpi3mr_sas_port_add() leaks a target device referenceCVE-2026-98128 · Linux kernel mpi3mr (target device refcount leak in mpi3mr_sas_port_add())Unscored
- Linux kernel mpi3mr: NULL dereference and sas_port leak when SAS port allocation failsCVE-2026-98129 · Linux kernel mpi3mr (Broadcom tri-mode SAS/SATA/NVMe HBA driver)Unscored
- Linux cgroup: task iterator can resurrect a zero-refcount dying task, giving a use-after-freeCVE-2026-98163 · Linux kernel cgroup task iterator (css_task_iter_next over dying_tasks)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.