GPU VulnDB

Database/Firmware, BMC & network fabric

Linux kernel RDS/IB: protocol version mismatch deadlocks the RDS connection workqueues

UnscoredCVE-2026-98257Firmware, BMC & network fabriccurated

Impact

When an RDS-over-IB peer negotiates a protocol version older than RDS_PROTOCOL_COMPAT_VERSION, the RDMA-CM event handler calls rds_conn_destroy() while holding c_cm_lock and then flushes shutdown work that needs the same lock. The two workers wait on each other and the RDS connection workqueues stall permanently. On a node using RDS over the InfiniBand/RoCE fabric this is a denial of service that does not clear itself: RDS connectivity is gone until the node is rebooted, and a node stuck this way has to be drained. The trigger is a peer-controlled protocol version on the fabric.

Who can reach it

Anyone able to initiate an RDS/IB connection to the node over the InfiniBand or RoCE fabric, including another tenant sharing that fabric. No authentication beyond fabric reachability. Only affects hosts with the RDS module loaded and in use.

What to do

Apply the stable fix that uses rds_conn_drop() instead of rds_conn_destroy() on the version-mismatch path - a kernel update and a node reboot, so drain the node first. If RDS is not used, blacklisting the rds and rds_rdma modules removes the exposure without a reboot of the workload. No vendor advisory or CVSS score in the record.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.