Impact
In the Linux kernel, a race condition exists in the Remote Direct Storage (RDS) subsystem. The function rds_cong_map_updated() uses waitqueue_active() without a memory barrier, while the counterpart waiter rds_cong_wait() performs the reverse without ordering. This allows an updater to observe an empty wait queue while the waiter still sees congestion, causing the updater to skip issuing a wake‑up. The consequence is that a sender blocked on a congested port can remain blocked indefinitely until the next congestion update or a signal arrives. The likely attack vector is an attacker sending specially crafted RDS packets that force the kernel to update a peer’s congestion map, thereby triggering the race and keeping the sender stalled. The result is a denial‑of‑service scenario where the blocked sender consumes CPU time and memory, potentially exhausting resources and degrading overall system performance.
Affected Systems
The vulnerability affects all Linux kernel releases prior to the patch that replaces waitqueue_active() with wq_has_sleeper() in rds_cong_map_updated(). No specific vendor or product version information is provided beyond the Linux kernel itself. Therefore, any system running an impacted kernel variant is potentially exposed.
Risk and Exploitability
The EPSS score is less than 1%, and the issue is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation but a non‑zero risk in environments that use RDS for RDMA communication. Exploitation would require network access to the target with the ability to send RDS frames; it does not rely on local privilege escalation. Given the denial‑of‑service nature and the resource exhaustion potential, the severity is moderate to high for affected workloads, especially on servers where RDS traffic is frequent.
OpenCVE Enrichment
Debian DLA
Debian DSA