PT-2026-94429 · Linux · Linux Kernel

CVE-2026-90081

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists in the Reliable Datagram Sockets (RDS) implementation. The function rds cong map updated() fails to ensure proper memory ordering when updating the congestion map and checking for waiters. Because atomic inc() does not provide ordering and waitqueue active() performs a plain load, a store-buffering pattern occurs. This allows the updater to perceive the wait queue as empty while a waiter still sees the port as congested, resulting in a missed wake-up signal. Consequently, a sender blocked in rds cong wait() or a waiter in rds poll() may remain blocked indefinitely until a subsequent congestion update or signal is received.
Recommendations Replace the use of waitqueue active() with wq has sleeper() within the rds cong map updated() function to ensure a full memory barrier is applied.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102839
CVE-2026-90081
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel