net/rds: don't let rds_conn_shutdown() consume a concurrent drop
In the Linux kernel, the following vulnerability has been resolved: net/rds: don't let rds_conn_shutdown() consume a concurrent drop rds_conn_shutdown() finishes by moving the path from RDS_CONN_DISCONNECTING to RDS_CONN_DOWN, and also accepts RDS_CONN_ERROR as the starting state of that final transition, so that a FIN processed in softirq context during the teardown does not derail the shutdown into a noisy error path. But consuming that RDS_CONN_ERROR also consumes the shutdown pass that came with it: rds_conn_path_drop() sets RDS_CONN_ERROR and then queues cp_down_w, and a pass that starts on a path already in RDS_CONN_DOWN is a no-op. For the FIN case that is harmless - the socket the FIN arrived on is the very socket the teardown just released. It is not harmless for a dropper that attached something to the path first. rds_tcp_accept_one() is such a dropper. Its path claim in rds_tcp_accept_one_path() transitions RDS_CONN_DOWN -> RDS_CONN_CONNECTING, and a concurrent drop - a FIN on a previous socket in softirq context, an administrative reset - can put the path into RDS_CONN_ERROR between that claim and the state check that follows, which accepts RDS_CONN_ERROR. The accept then installs the freshly accepted socket with rds_tcp_set_callbacks() while the queued teardown - which sampled tc->t_sock before this socket existed - is still running. rds_connect_path_complete() fails its transition to RDS_CONN_UP and drops the path again, queueing the pass that should reap the socket it just installed. If the in-flight shutdown's final transition consumes that drop's RDS_CONN_ERROR, the queued pass finds the path in RDS_CONN_DOWN and does nothing. The installed socket is never torn down: it sits established with its callbacks armed and its rds_tcp_connection on rds_tcp_tc_list, the peer sees a connection that nothing ever reads, and the path is wedged in RDS_CONN_DOWN until some later event drops it again. Reproduced with widened race windows as an ever-growing receive queue on a socket owned by a path stuck in RDS_CONN_DOWN, with the peer's send path wedged behind it. Make the final transition only DISCONNECTING -> DOWN. If it fails because the path is in RDS_CONN_ERROR, a drop raced the teardown: cancel the reconnect timer and clear RDS_RECONNECT_PENDING - the one piece of the skipped tail that must not be left behind - and return, letting the pass the drop queued finish the job: it tears down whatever attached to the path in the meantime, completes the transition to RDS_CONN_DOWN, and re-arms the reconnect from its own tail. The timer quiesce in that branch matters because the racing drop does not always queue that pass: rds_conn_path_drop() returns without queueing when a destroy is pending - exactly the situation during a netns teardown or module unload, when a FIN on the dying socket is processed while rds_conn_path_destroy() flushes cp_down_w. If the flushed pass is the one that takes this return, no later pass exists, and rds_conn_path_destroy() would find cp_conn_w still armed (WARN_ON) and then free a path whose reconnect timer can still fire. With the cancel in the branch, every exit of a shutdown pass leaves the timer quiesced no matter which pass completes the transition. The FIN case keeps making progress, one pass later and still without noisy logging. Any other state keeps today's rds_conn_path_error() handling; no current cp_state writer can leave a DISCONNECTING path in anything but RDS_CONN_ERROR (every other writer is a cmpxchg from a non-DISCONNECTING state), so that branch is defensive. On kernels without the preceding patches the same hazard exists with the sample-based quiesce; the fix applies there equally.
- Yayın
- 25 Eyl 2026
- Güncelleme
- 3 Eki 2026
- EPSS
- %0,2 · 7. yüzdelik
- CWE
- —
Takip etmek için giriş yap · Takip ettiğin kayıt KEV’e girer, istismarı çıkar ya da güncellenirse bildirim alırsın.
Rapor araçları
Aksiyon skoru
0
İzleyin
Şimdilik düşük öncelik.
- CVSS
- 0 / 40 · —
- CISA KEV
- 0 / 30 · Listede değil
- EPSS
- 0 / 30 · %0,2
Noroxi analizi
Bu kayıt için henüz Noroxi analizi yok
Veritabanındaki yüz binlerce zafiyetin tamamına elle analiz yazmıyoruz; bu dürüst olmazdı. Öne çıkan ve sahada etkisi olan zafiyetler için mekanizma, tespit ve kapatma adımlarını ekibimiz yazıyor.
Bu ürünü kullanıyoruz, yardım isteyinEtkilenen sistemler
—
Üreticinin bildirdiği sürümler
Kaydı açan otorite (Linux) tarafından bildirilen etkilenen sürüm aralıkları. NVD'nin CPE analizinden bağımsızdır ve genellikle ondan önce gelir.
Linux Linux
- 4.12etkilenir
- e97656d03ca0cea888a0b9d382abce8233771f31 ve sonrası · f777c602d3e15d3414b53f760147687bd56b03f2 öncesietkilenir · git
- e97656d03ca0cea888a0b9d382abce8233771f31 ve sonrası · 7cb11257aa3e5ef0bedfd5d55ac60bb00347aa97 öncesietkilenir · git
- e97656d03ca0cea888a0b9d382abce8233771f31 ve sonrası · 4980ce260205001d582a7b3cb5eab29877777fbc öncesietkilenir · git
- e97656d03ca0cea888a0b9d382abce8233771f31 ve sonrası · 0ec75c69918b7f6a1a5e3fb6442925246a9ec86b öncesietkilenir · git
- e97656d03ca0cea888a0b9d382abce8233771f31 ve sonrası · bd1cb197a07111ca8d4f4c21411c56a3c85a9797 öncesietkilenir · git
- e97656d03ca0cea888a0b9d382abce8233771f31 ve sonrası · 4cb9b6d3d31a2dbaa5469981c2c4c03e9acc7aca öncesietkilenir · git
- e97656d03ca0cea888a0b9d382abce8233771f31 ve sonrası · 2941561395066be856a53626d4ca973dd9c982b2 öncesietkilenir · git
- e97656d03ca0cea888a0b9d382abce8233771f31 ve sonrası · 260c6308fe2e19ad519389d44d582e292aecc3af öncesietkilenir · git
- 4.12 öncesietkilenmez · semver
Paket düzeyi etkilenme
OSV ve GitHub Advisory verisi: ekosistem, paket ve aralık. SBOM eşleşmesi bu tabloyu kullanır.
| Ekosistem | Paket | Etkilenen aralık | Düzeltme |
|---|---|---|---|
| Debian:12 | linux | tüm sürümler | — |
| Debian:12 | linux-6.12 | 6.12.111-1~deb12u1 öncesi | 6.12.111-1~deb12u1 |
| Debian:13 | linux | 6.12.111-1 öncesi | 6.12.111-1 |
| Debian:14 | linux | 7.2.7-1 öncesi | 7.2.7-1 |
Aynı üründe
linux: tüm kayıtlarAynı birincil ürünün en yüksek skorlu diğer kayıtları.
- CVE-2026-74705udp: fix potential use-after-free in tunnel segmentation40Planlayın
- CVE-2026-74612veth: fix skb length accounting after XDP frag adjustment40Planlayın
- CVE-2026-74475vxlan: use neigh_ha_snapshot() in route_shortcircuit()40Planlayın
- CVE-2026-74309vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler40Planlayın
- CVE-2026-74280crypto: marvell/octeontx - fix DMA cleanup using wrong loop index40Planlayın
- CVE-2026-74279crypto: cavium/cpt - fix DMA cleanup using wrong loop index40Planlayın
Düzeltme
Hangi sürüme geçmeli
Üretici, paket deposu ve Microsoft kayıtlarından derlenen düzeltme sürümleri. Yükseltmeden önce üreticinin notunu doğrulayın.
| Ürün / paket | Düzeltilmiş sürüm | Kaynak |
|---|---|---|
| Linux Linux | 0ec75c69918b7f6a1a5e3fb6442925246a9ec86b | Üretici (CNA) |
| Linux Linux | 260c6308fe2e19ad519389d44d582e292aecc3af | Üretici (CNA) |
| Linux Linux | 2941561395066be856a53626d4ca973dd9c982b2 | Üretici (CNA) |
| Linux Linux | 4980ce260205001d582a7b3cb5eab29877777fbc | Üretici (CNA) |
| Linux Linux | 4cb9b6d3d31a2dbaa5469981c2c4c03e9acc7aca | Üretici (CNA) |
| Linux Linux | 7cb11257aa3e5ef0bedfd5d55ac60bb00347aa97 | Üretici (CNA) |
| Linux Linux | bd1cb197a07111ca8d4f4c21411c56a3c85a9797 | Üretici (CNA) |
| Linux Linux | f777c602d3e15d3414b53f760147687bd56b03f2 | Üretici (CNA) |
| debian:linux | 6.12.111-1 · Debian:13 | Paket deposu (OSV) |
| debian:linux-6.12 | 6.12.111-1~deb12u1 · Debian:12 | Paket deposu (OSV) |
İstismar durumu
Bilinen kamuya açık istismar yok
Şu an kamuya açık bir istismar görülmedi. Bu, güvende olduğunuz anlamına gelmez; yalnızca eşiğin biraz daha yüksek olduğunu gösterir.
Araştırma bağlamı
Pentester ve araştırmacı için: saldırı profili, puan anlaşmazlığı, zaman çizelgesi, yama commit’leri, kredi, varyant ve zincir adayları, bug bounty kapsamı. Hepsi mevcut veriden türetilir; istismar kodu içermez.
Zaman çizelgesi
Yayından bugüne: kavram kanıtı, Metasploit modülü, CISA KEV ve düzeltme kaydı. Tarihler kaynakların bildirdiği tarihlerdir.
Yayın dışında tarihli olay yok.
FIRST EPSS günlük puanı; yalnızca 0,01 ve üstü değişimler kaydedilir (adım grafiği).
Yama ve commit bağlantıları
Referanslardaki commit, PR ve diff adresleri. Patch-diff ve varyant avı için başlangıç noktası; istismar değil, düzeltmedir.
Referanslarda commit ya da PR bağlantısı yok.
Kredi
Tüm araştırmacılarCNA kaydında adı geçen bulan, bildiren ve analistler. Ada tıkla, aynı araştırmacının diğer kayıtlarını gör.
CNA kaydında kredi yok.
Varyant adayları
Aynı üründe aynı zafiyet sınıfı, 18 ay içinde. Yama kök nedeni kapatmadıysa kardeş hata burada olur.
Gece hesaplanan ilişki yok.
Zincir adayları
Aynı üründe kimlik doğrulama atlatma ile yetki isteyen bir açık kısa aralıkla yayımlanmış: birlikte kimlik doğrulamasız bir yola dönüşebilir.
—
Bug bounty kapsamı
Bilinen herkese açık program yok.
Kaynak: bounty-targets-data (HackerOne, Bugcrowd, Intigriti, YesWeHack herkese açık listeleri).
Ulusal bildirim (Siber Güvenlik Başkanlığı / USOM)
Bu kaydı anan resmi güvenlik bildirimleri; çözüm önerisi kurumun sayfasında.
- TR-26-1184 · 28 Eyl 2026(Linux Kernel Güvenlik Bildirimi)
Teknik detay
Bu kayıt için CVSS vektörü yok; saldırı koşulları çıkarılamıyor.
Zayıflık sınıfı (CWE)
—
Saldırı bağlamı
Bu zafiyet sınıfının (CWE) MITRE CAPEC saldırı desenleri ve ATT&CK teknikleri. Tespit kuralı ve tehdit avı için başlangıç noktası.
Bu CWE için MITRE'de CAPEC/ATT&CK eşlemesi yok.
Değişiklik günlüğü
- Düzeltme✗ → ✓
Takip ettiğiniz kayıtlarda bu değişiklikler bildirim olarak da gelir. →
Referanslar
- git.kernel.org/stable/c/0ec75c69918b7f6a1a5e3fb6442925246a9ec86b
- git.kernel.org/stable/c/260c6308fe2e19ad519389d44d582e292aecc3af
- git.kernel.org/stable/c/2941561395066be856a53626d4ca973dd9c982b2
- git.kernel.org/stable/c/4980ce260205001d582a7b3cb5eab29877777fbc
- git.kernel.org/stable/c/4cb9b6d3d31a2dbaa5469981c2c4c03e9acc7aca
- git.kernel.org/stable/c/7cb11257aa3e5ef0bedfd5d55ac60bb00347aa97
- git.kernel.org/stable/c/bd1cb197a07111ca8d4f4c21411c56a3c85a9797
- git.kernel.org/stable/c/f777c602d3e15d3414b53f760147687bd56b03f2
Üretici bildirimleri ve resmî kayıtlar. İstismar/PoC bağlantıları bilinçli olarak dışarıda bırakıldı.