« Volver al listado

CVE-2026-90081

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net/rds: use wq_has_sleeper() in rds_cong_map_updated()

rds_cong_map_updated() runs after a peer's congestion map has been rewritten (by rds_tcp_cong_recv() and rds_ib_cong_recv(), or the clear-all in the loopback and IB send-completion paths). It bumps rds_cong_generation and then checks waitqueue_active() on map->m_waitq and on rds_poll_waitq to decide whether anyone needs waking. atomic_inc() carries no ordering and waitqueue_active() is a plain load, so nothing orders the map and generation stores before the wait queue reads. The waiters do the mirror image: rds_cong_wait() adds itself to m_waitq and then tests the port bit, and rds_poll() registers on rds_poll_waitq and then reads the generation. That is the store-buffering pattern described above waitqueue_active() in include/linux/wait.h - the updater can observe an empty wait queue while the waiter still observes the port as congested, and no wake-up is issued.

Leer descripción completaMostrar menos

rds_cong_wait() is an interruptible sleep with no timeout, so a sender blocked on a congested port stays blocked until the next congestion update from that peer arrives or a signal is delivered. A poll() waiter misses the map-updated notification the same way.

Use wq_has_sleeper(), which is waitqueue_active() preceded by the required full barrier, as rds_tcp_state_change() already does for the same pattern.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90081",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "922cb17a5c812fcc9ebee249f4109db099896941",
              "lessThan": "2a809d7896dbf18e1ecfbdd930f71c9fc298b16d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "922cb17a5c812fcc9ebee249f4109db099896941",
              "lessThan": "fa4b98e891fda28cc0638d809c6125ec63d8319d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "922cb17a5c812fcc9ebee249f4109db099896941",
              "lessThan": "0e169f6a2adeb17b5577ed7e8abd642465bb50ec",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "922cb17a5c812fcc9ebee249f4109db099896941",
              "lessThan": "42884bd8b8fd023d6a610a695bd5ddd1d5dece17",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "922cb17a5c812fcc9ebee249f4109db099896941",
              "lessThan": "a526214b9f0548ca0e53a6e0d1727d8ea9befc23",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "922cb17a5c812fcc9ebee249f4109db099896941",
              "lessThan": "bf2b8130723efcb5b86c3ddb6317c3a9b2a9cfc5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "922cb17a5c812fcc9ebee249f4109db099896941",
              "lessThan": "281f9fda2e06d6c211bb365a5379ed2e05cc2e21",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "922cb17a5c812fcc9ebee249f4109db099896941",
              "lessThan": "d4f484661961636eb90d287050959e613795f73a",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/rds/cong.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.30"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.30",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/rds/cong.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:16:57.423",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0e169f6a2adeb17b5577ed7e8abd642465bb50ec",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/281f9fda2e06d6c211bb365a5379ed2e05cc2e21",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2a809d7896dbf18e1ecfbdd930f71c9fc298b16d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/42884bd8b8fd023d6a610a695bd5ddd1d5dece17",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a526214b9f0548ca0e53a6e0d1727d8ea9befc23",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bf2b8130723efcb5b86c3ddb6317c3a9b2a9cfc5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d4f484661961636eb90d287050959e613795f73a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fa4b98e891fda28cc0638d809c6125ec63d8319d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/rds: use wq_has_sleeper() in rds_cong_map_updated()\n\nrds_cong_map_updated() runs after a peer's congestion map has been\nrewritten (by rds_tcp_cong_recv() and rds_ib_cong_recv(), or the\nclear-all in the loopback and IB send-completion paths).  It bumps\nrds_cong_generation and then checks waitqueue_active() on\nmap->m_waitq and on rds_poll_waitq to decide whether anyone needs\nwaking.  atomic_inc() carries no ordering and waitqueue_active() is a\nplain load, so nothing orders the map and generation stores before\nthe wait queue reads.  The waiters do the mirror image: rds_cong_wait()\nadds itself to m_waitq and then tests the port bit, and rds_poll()\nregisters on rds_poll_waitq and then reads the generation.  That is\nthe store-buffering pattern described above waitqueue_active() in\ninclude/linux/wait.h - the updater can observe an empty wait queue\nwhile the waiter still observes the port as congested, and no wake-up\nis issued.\n\nrds_cong_wait() is an interruptible sleep with no timeout, so a\nsender blocked on a congested port stays blocked until the next\ncongestion update from that peer arrives or a signal is delivered.\nA poll() waiter misses the map-updated notification the same way.\n\nUse wq_has_sleeper(), which is waitqueue_active() preceded by the\nrequired full barrier, as rds_tcp_state_change() already does for\nthe same pattern."
    }
  ],
  "lastModified": "2026-09-17T17:16:57.423",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}