PT-2026-106586 · Linux · Linux

CVE-2026-98257

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
rds: ib: use rds conn drop() on protocol version mismatch
rds ib cm connect complete() runs from the RDMA-CM event handler with conn->c cm lock held. When the peer negotiates a protocol version older than RDS PROTOCOL COMPAT VERSION, the handler calls rds conn destroy(), which is only safe in the rmmod path: it synchronously tears the connection down and flush work()es the shutdown work cp down w.
That shutdown work (rds conn shutdown()) needs cp cm lock, which is the very lock the event handler still holds, so the flush never completes: the two workers wait on each other and the RDS connection workqueues stall for good.
All other RDMA-CM failure paths (REJECTED, CONNECT ERROR, DISCONNECTED) use rds conn drop(), which marks the connection RDS CONN ERROR and schedules the shutdown work asynchronously. Use it here as well.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98257

Affected Products

Linux