PT-2026-106586 · Linux · Linux
CVE-2026-98257
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
rds: ib: use rds conn drop() on protocol version mismatch
rds ib cm connect complete() runs from the RDMA-CM event handler with
conn->c cm lock held. When the peer negotiates a protocol version
older than RDS PROTOCOL COMPAT VERSION, the handler calls
rds conn destroy(), which is only safe in the rmmod path: it
synchronously tears the connection down and flush work()es the
shutdown work cp down w.
That shutdown work (rds conn shutdown()) needs cp cm lock, which is
the very lock the event handler still holds, so the flush never
completes: the two workers wait on each other and the RDS connection
workqueues stall for good.
All other RDMA-CM failure paths (REJECTED, CONNECT ERROR,
DISCONNECTED) use rds conn drop(), which marks the connection
RDS CONN ERROR and schedules the shutdown work asynchronously. Use
it here as well.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux