PT-2026-98734 · Linux · Linux

CVE-2026-98071

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net/rds: clear cp flags bits individually in rds conn path reset()
rds conn path reset() wipes the whole flag word with a plain cp->cp flags = 0 store. Every other accessor of that word uses atomic bitops, and some of them can run concurrently with the reset: RDS LL SEND FULL is set from rds send xmit() and cleared from the transport completion paths, neither of which holds anything that excludes the shutdown worker. A plain store racing an atomic read-modify-write on the same word is a data race, and whichever side loses has its update silently discarded.
Clear the two bits the reset is actually responsible for instead. RDS IN XMIT and RDS RECV REFILL need no store at all here: they belong to the caller, rds conn shutdown(), which waits for both to be clear before calling the transport shutdown and this reset.
This also gives every bit in cp flags a single well-defined writer discipline, which the following patches rely on when they turn RDS IN XMIT and RDS RECV REFILL into bit locks held across the teardown: a blanket store mid-teardown would destroy lock ownership that an atomic clear preserves.
Oracle UEK carries the same conversion ("net/rds: Preserve essential connection state flags"), motivated by its asynchronous shutdown state machine, whose progress and destroy flags must survive the reset. UEK's variant also clears RDS IN XMIT and RDS RECV REFILL because there the reset runs as the final step of a teardown that owns both bits, making those clears its unlock. Upstream that release belongs in rds conn shutdown(): once a later patch in this series turns the two bits into locks held across the teardown, ending ownership needs release semantics and a wake-up that a plain clear inside the reset would not provide.
Based on Oracle UEK commit "net/rds: Preserve essential connection state flags" by Gerd Rausch.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98071

Affected Products

Linux