8.1

CVE-2026-98070

net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()

In the Linux kernel, the following vulnerability has been resolved:

net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()

rds_tcp_reset_callbacks() quiesces the transmit path by setting the
path state to RDS_CONN_RESETTING and then waiting for RDS_IN_XMIT to
be sampled clear before swapping the underlying socket and calling
rds_send_path_reset().

Sampling the bit clear is not the same as owning it: rds_send_xmit()
can re-acquire RDS_IN_XMIT right after the wait_event() returns.  Its
state recheck after taking the lock is a store-buffering pattern (the
resetter writes the state and reads the bit, the sender writes the
bit and reads the state) and acquire_in_xmit() is only an acquire
operation, so on weakly ordered architectures both sides can miss
each other's write and the transmit path then runs concurrently with
rds_send_path_reset() rewriting cp_xmit_* state - which is exactly
what the comment above rds_send_path_reset() tells its callers to
prevent.

Take the lock instead, hold it across the socket swap and
rds_send_path_reset(), and release it with a wake-up at the end.  The
lock-ordering constraint documented above the wait still holds: the
lock is acquired before lock_sock(), so a sender inside tcp_sendmsg()
can never be waited on while we hold the socket lock.

Two details of the old code go away with the same change:

 - t_sock is now read only after the lock is acquired.  The old code
   cached it before waiting; the teardown in rds_conn_shutdown()
   releases that socket and clears t_sock, so a pointer cached before
   the wait can be stale by the time the accept path resumes.  Reading
   it under RDS_IN_XMIT is what makes the exclusion complete once the
   teardown owns the same lock, which the next patch arranges; until
   then the teardown still only samples the bit, and the two paths
   remain as exposed to each other as they are today.

 - The old !osock early path called rds_send_path_reset() with no
   serialization at all.  It now runs under the lock like the normal
   path.  The conditional RDS_CONN_RESETTING transition of the
   previous patch happens before the socket check either way: a path
   found without a socket is either still connecting (its reconnect
   worker blocked on t_conn_path_lock) and legitimately goes
   RESETTING -> UP on the new socket, or it has been torn down
   meanwhile and is dropped.

The in-function comment describing the old wait-based quiesce is
rewritten to describe the lock-based one, and the stale block comment
above the function (which still described a return value and an
incomplete list of t_sock writers) is refreshed to name all four
writers - the connect, accept, teardown and swap paths - and what
serializes each of them.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 335b48d980f631fbc5b233cbb3625ac0c86d67cb
Version < 670af4e4a4de5e6bb5daee3838485571a0caa5fa
Status affected
Version 335b48d980f631fbc5b233cbb3625ac0c86d67cb
Version < 830a2e21b200c6b6fdccc63dd3f23932bf7a894b
Status affected
Version 335b48d980f631fbc5b233cbb3625ac0c86d67cb
Version < a05790cb4ff03f797d76906990b148d83f63e7a3
Status affected
Version 335b48d980f631fbc5b233cbb3625ac0c86d67cb
Version < d184e6dd4b8f3c20c018595fd09795a66b46c8ef
Status affected
Version 335b48d980f631fbc5b233cbb3625ac0c86d67cb
Version < d625112564c3e980e02504270222b49b82690cee
Status affected
Version 335b48d980f631fbc5b233cbb3625ac0c86d67cb
Version < 8e4c3b7844c906c7097b4cfedd9dd1f48c9a6a92
Status affected
Version 335b48d980f631fbc5b233cbb3625ac0c86d67cb
Version < 062d9e008c67289e8e1b221ecdd8f9d60566d012
Status affected
Version 335b48d980f631fbc5b233cbb3625ac0c86d67cb
Version < 02c5f9dc2efd823e061954d564ce00bacd1bebeb
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.7
Status affected
Version 0
Version < 4.7
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.34
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d625112564c3e980e02504270222b49b82690cee
https://git.kernel.org/stable/c/8e4c3b7844c906c7097b4cfedd9dd1f48c9a6a92
https://git.kernel.org/stable/c/062d9e008c67289e8e1b221ecdd8f9d60566d012
https://git.kernel.org/stable/c/02c5f9dc2efd823e061954d564ce00bacd1bebeb
https://git.kernel.org/stable/c/670af4e4a4de5e6bb5daee3838485571a0caa5fa
https://git.kernel.org/stable/c/830a2e21b200c6b6fdccc63dd3f23932bf7a894b
https://git.kernel.org/stable/c/a05790cb4ff03f797d76906990b148d83f63e7a3
https://git.kernel.org/stable/c/d184e6dd4b8f3c20c018595fd09795a66b46c8ef