-
CVE-2026-98071
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:24:12
- Zuletzt bearbeitet 03.10.2026 11:18:28
- Erkennungen
net/rds: clear cp_flags bits individually in rds_conn_path_reset()
In the Linux kernel, the following vulnerability has been resolved:
net/rds: clear cp_flags bits individually in rds_conn_path_reset()
rds_conn_path_reset() wipes the whole flag word with a plain
cp->cp_flags = 0 store. Every other accessor of that word uses
atomic bitops, and some of them can run concurrently with the reset:
RDS_LL_SEND_FULL is set from rds_send_xmit() and cleared from the
transport completion paths, neither of which holds anything that
excludes the shutdown worker. A plain store racing an atomic
read-modify-write on the same word is a data race, and whichever
side loses has its update silently discarded.
Clear the two bits the reset is actually responsible for instead.
RDS_IN_XMIT and RDS_RECV_REFILL need no store at all here: they
belong to the caller, rds_conn_shutdown(), which waits for both to be
clear before calling the transport shutdown and this reset.
This also gives every bit in cp_flags a single well-defined writer
discipline, which the following patches rely on when they turn
RDS_IN_XMIT and RDS_RECV_REFILL into bit locks held across the
teardown: a blanket store mid-teardown would destroy lock ownership
that an atomic clear preserves.
Oracle UEK carries the same conversion ("net/rds: Preserve essential
connection state flags"), motivated by its asynchronous shutdown
state machine, whose progress and destroy flags must survive the
reset. UEK's variant also clears RDS_IN_XMIT and RDS_RECV_REFILL
because there the reset runs as the final step of a teardown that
owns both bits, making those clears its unlock. Upstream that
release belongs in rds_conn_shutdown(): once a later patch in this
series turns the two bits into locks held across the teardown, ending
ownership needs release semantics and a wake-up that a plain clear
inside the reset would not provide.
Based on Oracle UEK commit "net/rds: Preserve essential connection
state flags" by Gerd Rausch.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version <
c9a7c1eb0ad41dcf004a9e870e452cafedcd9172
Status
affected
Version
00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version <
b767b48614c38687d717082860de7aa46f3b142c
Status
affected
Version
00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version <
b7dc5da660eb5ffa7f7b4d33f2c74cb71c6edd6c
Status
affected
Version
00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version <
b8a8b6d25e7426a638c60eaba2129c0664131e84
Status
affected
Version
00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version <
ed3ee0ac4aafda50c2f4381eb973beefeb7879ac
Status
affected
Version
00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version <
6b8d7563c28b8112e6e54abe413b028ef3f8c549
Status
affected
Version
00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version <
cb62aa8f04655a4df487913949719c0a1266ed73
Status
affected
Version
00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version <
103c4b13c4f50322910078d1c02f29334a574122
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.30
Status
affected
Version
0
Version <
2.6.30
Status
unaffected
Version <=
5.10.*
Version
5.10.271
Status
unaffected
Version <=
5.15.*
Version
5.15.222
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.054 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/ed3ee0ac4aafda50c2f4381eb973beefeb7879ac
https://git.kernel.org/stable/c/6b8d7563c28b8112e6e54abe413b028ef3f8c549
https://git.kernel.org/stable/c/cb62aa8f04655a4df487913949719c0a1266ed73
https://git.kernel.org/stable/c/103c4b13c4f50322910078d1c02f29334a574122
https://git.kernel.org/stable/c/b767b48614c38687d717082860de7aa46f3b142c
https://git.kernel.org/stable/c/b7dc5da660eb5ffa7f7b4d33f2c74cb71c6edd6c
https://git.kernel.org/stable/c/b8a8b6d25e7426a638c60eaba2129c0664131e84
https://git.kernel.org/stable/c/c9a7c1eb0ad41dcf004a9e870e452cafedcd9172