๐Ÿ” CVE Alert

CVE-2026-98071

UNKNOWN 0.0

net/rds: clear cp_flags bits individually in rds_conn_path_reset()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/rds: clear cp_flags bits individually in rds_conn_path_reset() rds_conn_path_reset() wipes the whole flag word with a plain cp->cp_flags = 0 store. Every other accessor of that word uses atomic bitops, and some of them can run concurrently with the reset: RDS_LL_SEND_FULL is set from rds_send_xmit() and cleared from the transport completion paths, neither of which holds anything that excludes the shutdown worker. A plain store racing an atomic read-modify-write on the same word is a data race, and whichever side loses has its update silently discarded. Clear the two bits the reset is actually responsible for instead. RDS_IN_XMIT and RDS_RECV_REFILL need no store at all here: they belong to the caller, rds_conn_shutdown(), which waits for both to be clear before calling the transport shutdown and this reset. This also gives every bit in cp_flags a single well-defined writer discipline, which the following patches rely on when they turn RDS_IN_XMIT and RDS_RECV_REFILL into bit locks held across the teardown: a blanket store mid-teardown would destroy lock ownership that an atomic clear preserves. Oracle UEK carries the same conversion ("net/rds: Preserve essential connection state flags"), motivated by its asynchronous shutdown state machine, whose progress and destroy flags must survive the reset. UEK's variant also clears RDS_IN_XMIT and RDS_RECV_REFILL because there the reset runs as the final step of a teardown that owns both bits, making those clears its unlock. Upstream that release belongs in rds_conn_shutdown(): once a later patch in this series turns the two bits into locks held across the teardown, ending ownership needs release semantics and a wake-up that a plain clear inside the reset would not provide. Based on Oracle UEK commit "net/rds: Preserve essential connection state flags" by Gerd Rausch.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
00e0f34c616603ba6500f41943cbf89eb4a8a5be < ed3ee0ac4aafda50c2f4381eb973beefeb7879ac 00e0f34c616603ba6500f41943cbf89eb4a8a5be < 6b8d7563c28b8112e6e54abe413b028ef3f8c549 00e0f34c616603ba6500f41943cbf89eb4a8a5be < cb62aa8f04655a4df487913949719c0a1266ed73 00e0f34c616603ba6500f41943cbf89eb4a8a5be < 103c4b13c4f50322910078d1c02f29334a574122
Linux / Linux
2.6.30

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ed3ee0ac4aafda50c2f4381eb973beefeb7879ac git.kernel.org: https://git.kernel.org/stable/c/6b8d7563c28b8112e6e54abe413b028ef3f8c549 git.kernel.org: https://git.kernel.org/stable/c/cb62aa8f04655a4df487913949719c0a1266ed73 git.kernel.org: https://git.kernel.org/stable/c/103c4b13c4f50322910078d1c02f29334a574122