PT-2026-94429 · Linux · Linux Kernel
CVE-2026-90081
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A race condition exists in the Reliable Datagram Sockets (RDS) implementation. The function
rds cong map updated() fails to ensure proper memory ordering when updating the congestion map and checking for waiters. Because atomic inc() does not provide ordering and waitqueue active() performs a plain load, a store-buffering pattern occurs. This allows the updater to perceive the wait queue as empty while a waiter still sees the port as congested, resulting in a missed wake-up signal. Consequently, a sender blocked in rds cong wait() or a waiter in rds poll() may remain blocked indefinitely until a subsequent congestion update or signal is received.Recommendations
Replace the use of
waitqueue active() with wq has sleeper() within the rds cong map updated() function to ensure a full memory barrier is applied.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel