« Volver al listado

CVE-2026-98071

Estado: En análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net/rds: clear cp_flags bits individually in rds_conn_path_reset()

rds_conn_path_reset() wipes the whole flag word with a plain cp->cp_flags = 0 store. Every other accessor of that word uses atomic bitops, and some of them can run concurrently with the reset: RDS_LL_SEND_FULL is set from rds_send_xmit() and cleared from the transport completion paths, neither of which holds anything that excludes the shutdown worker. A plain store racing an atomic read-modify-write on the same word is a data race, and whichever side loses has its update silently discarded.

Leer descripción completaMostrar menos

Clear the two bits the reset is actually responsible for instead. RDS_IN_XMIT and RDS_RECV_REFILL need no store at all here: they belong to the caller, rds_conn_shutdown(), which waits for both to be clear before calling the transport shutdown and this reset.

This also gives every bit in cp_flags a single well-defined writer discipline, which the following patches rely on when they turn RDS_IN_XMIT and RDS_RECV_REFILL into bit locks held across the teardown: a blanket store mid-teardown would destroy lock ownership that an atomic clear preserves.

Oracle UEK carries the same conversion ("net/rds: Preserve essential connection state flags"), motivated by its asynchronous shutdown state machine, whose progress and destroy flags must survive the reset. UEK's variant also clears RDS_IN_XMIT and RDS_RECV_REFILL because there the reset runs as the final step of a teardown that owns both bits, making those clears its unlock. Upstream that release belongs in rds_conn_shutdown(): once a later patch in this series turns the two bits into locks held across the teardown, ending ownership needs release semantics and a wake-up that a plain clear inside the reset would not provide.

Based on Oracle UEK commit "net/rds: Preserve essential connection state flags" by Gerd Rausch.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98071",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "00e0f34c616603ba6500f41943cbf89eb4a8a5be",
              "lessThan": "c9a7c1eb0ad41dcf004a9e870e452cafedcd9172",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "00e0f34c616603ba6500f41943cbf89eb4a8a5be",
              "lessThan": "b767b48614c38687d717082860de7aa46f3b142c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "00e0f34c616603ba6500f41943cbf89eb4a8a5be",
              "lessThan": "b7dc5da660eb5ffa7f7b4d33f2c74cb71c6edd6c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "00e0f34c616603ba6500f41943cbf89eb4a8a5be",
              "lessThan": "b8a8b6d25e7426a638c60eaba2129c0664131e84",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "00e0f34c616603ba6500f41943cbf89eb4a8a5be",
              "lessThan": "ed3ee0ac4aafda50c2f4381eb973beefeb7879ac",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "00e0f34c616603ba6500f41943cbf89eb4a8a5be",
              "lessThan": "6b8d7563c28b8112e6e54abe413b028ef3f8c549",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "00e0f34c616603ba6500f41943cbf89eb4a8a5be",
              "lessThan": "cb62aa8f04655a4df487913949719c0a1266ed73",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "00e0f34c616603ba6500f41943cbf89eb4a8a5be",
              "lessThan": "103c4b13c4f50322910078d1c02f29334a574122",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/rds/connection.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.30"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.30",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/rds/connection.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:36.327",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/103c4b13c4f50322910078d1c02f29334a574122",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6b8d7563c28b8112e6e54abe413b028ef3f8c549",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b767b48614c38687d717082860de7aa46f3b142c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b7dc5da660eb5ffa7f7b4d33f2c74cb71c6edd6c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b8a8b6d25e7426a638c60eaba2129c0664131e84",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c9a7c1eb0ad41dcf004a9e870e452cafedcd9172",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cb62aa8f04655a4df487913949719c0a1266ed73",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ed3ee0ac4aafda50c2f4381eb973beefeb7879ac",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/rds: clear cp_flags bits individually in rds_conn_path_reset()\n\nrds_conn_path_reset() wipes the whole flag word with a plain\ncp->cp_flags = 0 store.  Every other accessor of that word uses\natomic bitops, and some of them can run concurrently with the reset:\nRDS_LL_SEND_FULL is set from rds_send_xmit() and cleared from the\ntransport completion paths, neither of which holds anything that\nexcludes the shutdown worker.  A plain store racing an atomic\nread-modify-write on the same word is a data race, and whichever\nside loses has its update silently discarded.\n\nClear the two bits the reset is actually responsible for instead.\nRDS_IN_XMIT and RDS_RECV_REFILL need no store at all here: they\nbelong to the caller, rds_conn_shutdown(), which waits for both to be\nclear before calling the transport shutdown and this reset.\n\nThis also gives every bit in cp_flags a single well-defined writer\ndiscipline, which the following patches rely on when they turn\nRDS_IN_XMIT and RDS_RECV_REFILL into bit locks held across the\nteardown: a blanket store mid-teardown would destroy lock ownership\nthat an atomic clear preserves.\n\nOracle UEK carries the same conversion (\"net/rds: Preserve essential\nconnection state flags\"), motivated by its asynchronous shutdown\nstate machine, whose progress and destroy flags must survive the\nreset.  UEK's variant also clears RDS_IN_XMIT and RDS_RECV_REFILL\nbecause there the reset runs as the final step of a teardown that\nowns both bits, making those clears its unlock.  Upstream that\nrelease belongs in rds_conn_shutdown(): once a later patch in this\nseries turns the two bits into locks held across the teardown, ending\nownership needs release semantics and a wake-up that a plain clear\ninside the reset would not provide.\n\nBased on Oracle UEK commit \"net/rds: Preserve essential connection\nstate flags\" by Gerd Rausch."
    }
  ],
  "lastModified": "2026-10-03T11:18:28.300",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}