7.8

CVE-2026-43494

net/rds: reset op_nents when zerocopy page pin fails

In the Linux kernel, the following vulnerability has been resolved:

net/rds: reset op_nents when zerocopy page pin fails

When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(),
the pinned pages are released with put_page(), and
rm->data.op_mmp_znotifier is cleared.  But we fail to properly
clear rm->data.op_nents.

Later when rds_message_purge() is called from rds_sendmsg() the
cleanup loop iterates over the incorrectly non zero number of
op_nents and frees them again.

Fix this by properly resetting op_nents when it should be in
rds_message_zcopy_from_user().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3
Version < c6e51512a784c4a7b86e1a044988696e3b3721fa
Status affected
Version 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3
Version < 03014551938a0887fa55f18ce49b70158a9c0113
Status affected
Version 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3
Version < d84ce1786ce40fdd3dd98db47aec5527817e1ef6
Status affected
Version 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3
Version < 9115669faedccdda100428e2d26fd0aac8c50799
Status affected
Version 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3
Version < 0bbbff00a15b1df2cac9014d6cf4b6890f473353
Status affected
Version 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3
Version < 640e37f58f991546a87540d067279c2c1fa9fe51
Status affected
Version 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3
Version < 290e833d1acb1093bc121fcdc97f5e6161157479
Status affected
Version 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3
Version < e174929793195e0cd6a4adb0cad731b39f9019b4
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.17
Status affected
Version 0
Version < 4.17
Status unaffected
Version <= 5.10.*
Version 5.10.258
Status unaffected
Version <= 5.15.*
Version 5.15.209
Status unaffected
Version <= 6.1.*
Version 6.1.175
Status unaffected
Version <= 6.6.*
Version 6.6.141
Status unaffected
Version <= 6.12.*
Version 6.12.91
Status unaffected
Version <= 6.18.*
Version 6.18.33
Status unaffected
Version <= 7.0.*
Version 7.0.10
Status unaffected
Version <= *
Version 7.1-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.025
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.