-

CVE-2026-98071

net/rds: clear cp_flags bits individually in rds_conn_path_reset()

In the Linux kernel, the following vulnerability has been resolved:

net/rds: clear cp_flags bits individually in rds_conn_path_reset()

rds_conn_path_reset() wipes the whole flag word with a plain
cp->cp_flags = 0 store.  Every other accessor of that word uses
atomic bitops, and some of them can run concurrently with the reset:
RDS_LL_SEND_FULL is set from rds_send_xmit() and cleared from the
transport completion paths, neither of which holds anything that
excludes the shutdown worker.  A plain store racing an atomic
read-modify-write on the same word is a data race, and whichever
side loses has its update silently discarded.

Clear the two bits the reset is actually responsible for instead.
RDS_IN_XMIT and RDS_RECV_REFILL need no store at all here: they
belong to the caller, rds_conn_shutdown(), which waits for both to be
clear before calling the transport shutdown and this reset.

This also gives every bit in cp_flags a single well-defined writer
discipline, which the following patches rely on when they turn
RDS_IN_XMIT and RDS_RECV_REFILL into bit locks held across the
teardown: a blanket store mid-teardown would destroy lock ownership
that an atomic clear preserves.

Oracle UEK carries the same conversion ("net/rds: Preserve essential
connection state flags"), motivated by its asynchronous shutdown
state machine, whose progress and destroy flags must survive the
reset.  UEK's variant also clears RDS_IN_XMIT and RDS_RECV_REFILL
because there the reset runs as the final step of a teardown that
owns both bits, making those clears its unlock.  Upstream that
release belongs in rds_conn_shutdown(): once a later patch in this
series turns the two bits into locks held across the teardown, ending
ownership needs release semantics and a wake-up that a plain clear
inside the reset would not provide.

Based on Oracle UEK commit "net/rds: Preserve essential connection
state flags" by Gerd Rausch.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version < c9a7c1eb0ad41dcf004a9e870e452cafedcd9172
Status affected
Version 00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version < b767b48614c38687d717082860de7aa46f3b142c
Status affected
Version 00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version < b7dc5da660eb5ffa7f7b4d33f2c74cb71c6edd6c
Status affected
Version 00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version < b8a8b6d25e7426a638c60eaba2129c0664131e84
Status affected
Version 00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version < ed3ee0ac4aafda50c2f4381eb973beefeb7879ac
Status affected
Version 00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version < 6b8d7563c28b8112e6e54abe413b028ef3f8c549
Status affected
Version 00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version < cb62aa8f04655a4df487913949719c0a1266ed73
Status affected
Version 00e0f34c616603ba6500f41943cbf89eb4a8a5be
Version < 103c4b13c4f50322910078d1c02f29334a574122
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.30
Status affected
Version 0
Version < 2.6.30
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ed3ee0ac4aafda50c2f4381eb973beefeb7879ac
https://git.kernel.org/stable/c/6b8d7563c28b8112e6e54abe413b028ef3f8c549
https://git.kernel.org/stable/c/cb62aa8f04655a4df487913949719c0a1266ed73
https://git.kernel.org/stable/c/103c4b13c4f50322910078d1c02f29334a574122
https://git.kernel.org/stable/c/b767b48614c38687d717082860de7aa46f3b142c
https://git.kernel.org/stable/c/b7dc5da660eb5ffa7f7b4d33f2c74cb71c6edd6c
https://git.kernel.org/stable/c/b8a8b6d25e7426a638c60eaba2129c0664131e84
https://git.kernel.org/stable/c/c9a7c1eb0ad41dcf004a9e870e452cafedcd9172