CVE-2026-98257
Received
Received - Intake
RDS Protocol Version Mismatch Connection Drop Failure
Vulnerability report for CVE-2026-98257, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
rds: ib: use rds_conn_drop() on protocol version mismatch
rds_ib_cm_connect_complete() runs from the RDMA-CM event handler with
conn->c_cm_lock held. When the peer negotiates a protocol version
older than RDS_PROTOCOL_COMPAT_VERSION, the handler calls
rds_conn_destroy(), which is only safe in the rmmod path: it
synchronously tears the connection down and flush_work()es the
shutdown work cp_down_w.
That shutdown work (rds_conn_shutdown()) needs cp_cm_lock, which is
the very lock the event handler still holds, so the flush never
completes: the two workers wait on each other and the RDS connection
workqueues stall for good.
All other RDMA-CM failure paths (REJECTED, CONNECT_ERROR,
DISCONNECTED) use rds_conn_drop(), which marks the connection
RDS_CONN_ERROR and schedules the shutdown work asynchronously. Use
it here as well.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | f147dd9ecabf23fd63d2562ffe64252a0453ecde |
| Linux | Linux | f147dd9ecabf23fd63d2562ffe64252a0453ecde |
| Linux | Linux | f147dd9ecabf23fd63d2562ffe64252a0453ecde |
| Linux | Linux | f147dd9ecabf23fd63d2562ffe64252a0453ecde |
| Linux | Linux | f147dd9ecabf23fd63d2562ffe64252a0453ecde |
| Linux | Linux | f147dd9ecabf23fd63d2562ffe64252a0453ecde |
| Linux | Linux | f147dd9ecabf23fd63d2562ffe64252a0453ecde |
| Linux | Linux | f147dd9ecabf23fd63d2562ffe64252a0453ecde |
| Linux | Linux | 2.6.37 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |