HIGH Introduced in 2.6.37
rds ProtocolVersion Deadlock
CVE-2026-98257
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
KernelScan AI6.5MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: rds: ib: use rds_conn_drop() on protocol version mismatch rds_ib_cm_connect_complete() runs from the RDMA-CM event handler with conn->c_cm_lock held. When the peer negotiates a protocol version older than RDS_PROTOCOL_COMPAT_VERSION, the handler calls rds_conn_destroy(), which is only safe in the rmmod path: it synchronously tears the connection down and flush_work()es the shutdown work cp_down_w. That shutdown work (rds_conn_shutdown()) needs cp_cm_lock, which is the very lock the event handler still holds, so the flush never completes: the two workers wait on each other and the RDS connection workqueues stall for good. All other RDMA-CM failure paths (REJECTED, CONNECT_ERROR, DISCONNECTED) use rds_conn_drop(), which marks the connection RDS_CONN_ERROR and schedules the shutdown work asynchronously. Use it here as well.
02KernelScan AI Analysis
Risk summary
A remote peer on the same RDMA fabric (InfiniBand or RoCE) can permanently stall the target's RDS connection workqueues by negotiating an outdated protocol version during connection setup. The deadlock is a denial of service with no confidentiality or integrity impact. Systems without RDMA hardware or the RDS module loaded are not affected.
Vulnerability analysis
When a peer negotiates an RDS protocol version older than the minimum compatible version during connection setup, the RDMA connection event handler attempts to synchronously tear down the connection while still holding a lock that the teardown worker also needs. Both threads block waiting for each other indefinitely, permanently stalling the RDS connection workqueues. The fix replaces the synchronous teardown call with an asynchronous connection drop, consistent with all other RDMA connection failure paths, which marks the connection as errored and schedules the shutdown work without holding the lock. The bug is reachable from any peer on the same RDMA fabric and also by a local process that initiates an RDS connection to a malicious peer; no special privileges are required.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 2.6.37 | 5.10.271 | 424019be3f63 |
| 5.15 | 2.6.37 | 5.15.222 | 14fb90067d13 |
| 6.1 | 2.6.37 | 6.1.189 | 344c72a0bc27 |
| 6.6 | 2.6.37 | 6.6.158 | b5c9f2951d33 |
| 6.12 | 2.6.37 | 6.12.112 | d392b16acd09 |
| 6.18 | 2.6.37 | 6.18.54 | 65ca0a503715 |
| 7.2 | 2.6.37 | 7.2.8 | 7d8c22cb2cb1 |
| mainline | 2.6.37 | 7.3-rc4 | f97d8c7bab78 |