PT-2026-106586 · Linux · Linux
CVE-2026-98257
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
rds: ib: use rds conn drop() on protocol version mismatch
rds ib cm connect complete() runs from the RDMA-CM event handler with
conn->c cm lock held. When the peer negotiates a protocol version
older than RDS PROTOCOL COMPAT VERSION, the handler calls
rds conn destroy(), which is only safe in the rmmod path: it
synchronously tears the connection down and flush work()es the
shutdown work cp down w.
That shutdown work (rds conn shutdown()) needs cp cm lock, which is
the very lock the event handler still holds, so the flush never
completes: the two workers wait on each other and the RDS connection
workqueues stall for good.
All other RDMA-CM failure paths (REJECTED, CONNECT ERROR,
DISCONNECTED) use rds conn drop(), which marks the connection
RDS CONN ERROR and schedules the shutdown work asynchronously. Use
it here as well.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux