Description
In the Linux kernel, the following vulnerability has been resolved:

net/rds: use wq_has_sleeper() in rds_cong_map_updated()

rds_cong_map_updated() runs after a peer's congestion map has been
rewritten (by rds_tcp_cong_recv() and rds_ib_cong_recv(), or the
clear-all in the loopback and IB send-completion paths). It bumps
rds_cong_generation and then checks waitqueue_active() on
map->m_waitq and on rds_poll_waitq to decide whether anyone needs
waking. atomic_inc() carries no ordering and waitqueue_active() is a
plain load, so nothing orders the map and generation stores before
the wait queue reads. The waiters do the mirror image: rds_cong_wait()
adds itself to m_waitq and then tests the port bit, and rds_poll()
registers on rds_poll_waitq and then reads the generation. That is
the store-buffering pattern described above waitqueue_active() in
include/linux/wait.h - the updater can observe an empty wait queue
while the waiter still observes the port as congested, and no wake-up
is issued.

rds_cong_wait() is an interruptible sleep with no timeout, so a
sender blocked on a congested port stays blocked until the next
congestion update from that peer arrives or a signal is delivered.
A poll() waiter misses the map-updated notification the same way.

Use wq_has_sleeper(), which is waitqueue_active() preceded by the
required full barrier, as rds_tcp_state_change() already does for
the same pattern.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service due to race condition in RDS congestion map updates
Action: Patch
AI Analysis

Impact

In the Linux kernel, a race condition exists in the Remote Direct Storage (RDS) subsystem. The function rds_cong_map_updated() uses waitqueue_active() without a memory barrier, while the counterpart waiter rds_cong_wait() performs the reverse without ordering. This allows an updater to observe an empty wait queue while the waiter still sees congestion, causing the updater to skip issuing a wake‑up. The consequence is that a sender blocked on a congested port can remain blocked indefinitely until the next congestion update or a signal arrives. The likely attack vector is an attacker sending specially crafted RDS packets that force the kernel to update a peer’s congestion map, thereby triggering the race and keeping the sender stalled. The result is a denial‑of‑service scenario where the blocked sender consumes CPU time and memory, potentially exhausting resources and degrading overall system performance.

Affected Systems

The vulnerability affects all Linux kernel releases prior to the patch that replaces waitqueue_active() with wq_has_sleeper() in rds_cong_map_updated(). No specific vendor or product version information is provided beyond the Linux kernel itself. Therefore, any system running an impacted kernel variant is potentially exposed.

Risk and Exploitability

The EPSS score is less than 1%, and the issue is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation but a non‑zero risk in environments that use RDS for RDMA communication. Exploitation would require network access to the target with the ability to send RDS frames; it does not rely on local privilege escalation. Given the denial‑of‑service nature and the resource exhaustion potential, the severity is moderate to high for affected workloads, especially on servers where RDS traffic is frequent.

Generated by OpenCVE AI on September 20, 2026 at 04:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the remedy for rds_cong_map_updated()
  • If an immediate kernel upgrade is not possible, disable the RDS protocol or its congestion mechanisms on hosts that do not require RDMA traffic, for example by setting sysctl values or removing the rds kernel module
  • For systems that must keep RDS enabled, monitor RDS traffic for unusually high congestion update rates and throttle or block suspicious packets using firewall rules
  • Implement alerts for prolonged blocking of RDS senders, and consider applying kernel hardening patches to enforce proper memory ordering if available

Generated by OpenCVE AI on September 20, 2026 at 04:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/rds: use wq_has_sleeper() in rds_cong_map_updated() rds_cong_map_updated() runs after a peer's congestion map has been rewritten (by rds_tcp_cong_recv() and rds_ib_cong_recv(), or the clear-all in the loopback and IB send-completion paths). It bumps rds_cong_generation and then checks waitqueue_active() on map->m_waitq and on rds_poll_waitq to decide whether anyone needs waking. atomic_inc() carries no ordering and waitqueue_active() is a plain load, so nothing orders the map and generation stores before the wait queue reads. The waiters do the mirror image: rds_cong_wait() adds itself to m_waitq and then tests the port bit, and rds_poll() registers on rds_poll_waitq and then reads the generation. That is the store-buffering pattern described above waitqueue_active() in include/linux/wait.h - the updater can observe an empty wait queue while the waiter still observes the port as congested, and no wake-up is issued. rds_cong_wait() is an interruptible sleep with no timeout, so a sender blocked on a congested port stays blocked until the next congestion update from that peer arrives or a signal is delivered. A poll() waiter misses the map-updated notification the same way. Use wq_has_sleeper(), which is waitqueue_active() preceded by the required full barrier, as rds_tcp_state_change() already does for the same pattern.
Title net/rds: use wq_has_sleeper() in rds_cong_map_updated()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:58.866Z

Reserved: 2026-09-11T19:38:34.785Z

Link: CVE-2026-90081

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:57.423

Modified: 2026-09-17T17:16:57.423

Link: CVE-2026-90081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:18Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')