Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98257— rds: ib: use rds_conn_drop() on protocol version mismatch

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: rds: ib: 在协议版本不匹配时使用 rds_conn_drop() 函数在 RDMA-CM 事件处理程序中执行,并持有 锁。当对端协商出的协议版本低于 时,该处理程序会调用 。而 仅在模块卸载(rmmod)路径中是安全的,因为它会同步地拆除连接,并通过 等待关闭工作项( )执行完毕。 然而,该关闭工作(即 )需要获取 锁,但事件处理程序仍然持有此锁。因此, 永远不会完成:两个工作项相互等待,导致 RDS 连接的工作队列永久停滞。 其他所有 RDMA-CM 失败路径(如

CVSS 7.5 · High EPSS 0.53% · P43

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux f147dd9ecabf23fd63d2562ffe64252a0453ecde< 424019be3f637da76b74f44a40034669acbb166f affected
f147dd9ecabf23fd63d2562ffe64252a0453ecde< 14fb90067d13f4494cff0f03243fae3cf2911cbc affected
f147dd9ecabf23fd63d2562ffe64252a0453ecde< 344c72a0bc2703a6de4918ed935850e07dae3af2 affected
f147dd9ecabf23fd63d2562ffe64252a0453ecde< b5c9f2951d330d4a198a64d6e60f79b4bd6ef078 affected
f147dd9ecabf23fd63d2562ffe64252a0453ecde< d392b16acd0908f077289aad8bba066ff16de336 affected
f147dd9ecabf23fd63d2562ffe64252a0453ecde< 65ca0a5037152a5a80b8fe6aac80eb80458be573 affected
f147dd9ecabf23fd63d2562ffe64252a0453ecde< 7d8c22cb2cb1efb5e830a4545c76abf7b35cc2e8 affected
f147dd9ecabf23fd63d2562ffe64252a0453ecde< f97d8c7bab7843631206a114986c9059da03efeb affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98257

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
rds: ib: use rds_conn_drop() on protocol version mismatch
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: rds: ib: use rds_conn_drop() on protocol version mismatch rds_ib_cm_connect_complete() runs from the RDMA-CM event handler with conn->c_cm_lock held. When the peer negotiates a protocol version older than RDS_PROTOCOL_COMPAT_VERSION, the handler calls rds_conn_destroy(), which is only safe in the rmmod path: it synchronously tears the connection down and flush_work()es the shutdown work cp_down_w. That shutdown work (rds_conn_shutdown()) needs cp_cm_lock, which is the very lock the event handler still holds, so the flush never completes: the two workers wait on each other and the RDS connection workqueues stall for good. All other RDMA-CM failure paths (REJECTED, CONNECT_ERROR, DISCONNECTED) use rds_conn_drop(), which marks the connection RDS_CONN_ERROR and schedules the shutdown work asynchronously. Use it here as well.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux f147dd9ecabf23fd63d2562ffe64252a0453ecde ~ 424019be3f637da76b74f44a40034669acbb166f -
Linux Linux 2.6.37 -

II. Public POCs for CVE-2026-98257

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98257

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98257 (7)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98257

No comments yet


Leave a comment