* CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
@ 2026-06-24 7:13 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-06-24 7:13 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
rds_ib_xmit_atomic() always programs a masked atomic opcode
(IB_WR_MASKED_ATOMIC_CMP_AND_SWP or IB_WR_MASKED_ATOMIC_FETCH_AND_ADD)
for every RDS atomic cmsg. But the completion-side switch in
rds_ib_send_unmap_op() only handles the non-masked opcodes, so a masked
atomic completion falls through to default and returns rm == NULL while
send->s_op is left set. rds_ib_send_cqe_handler() then dereferences the
NULL rm via rm->m_final_op, oopsing in softirq context. An unprivileged
AF_RDS sendmsg() of an atomic cmsg over an active RDS/IB connection
triggers it; on hardware that natively accepts masked atomics (mlx4,
mlx5) no extra setup is needed.
RDS/IB: rds_ib_send_unmap_op: unexpected opcode 0xd in WR!
Oops: general protection fault [#1] SMP KASAN
KASAN: null-ptr-deref in range [0x0000000000000190-0x0000000000000197]
RIP: rds_ib_send_cqe_handler+0x25c/0xb10 (net/rds/ib_send.c:282)
Call Trace:
<IRQ>
rds_ib_send_cqe_handler (net/rds/ib_send.c:282)
poll_scq (net/rds/ib_cm.c:274)
rds_ib_tasklet_fn_send (net/rds/ib_cm.c:294)
tasklet_action_common (kernel/softirq.c:943)
handle_softirqs (kernel/softirq.c:573)
run_ksoftirqd (kernel/softirq.c:479)
</IRQ>
Kernel panic - not syncing: Fatal exception in interrupt
Handle the masked atomic opcodes in the same case as the non-masked
ones: they map to the same struct rds_message.atomic union member, so
the existing container_of()/rds_ib_send_unmap_atomic() body is correct
for them.
The Linux kernel CVE team has assigned CVE-2026-52939 to this issue.
Affected and fixed versions
===========================
Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 5.10.259 with commit a0148342badd8c9b2e46551766a27cb76c82e715
Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 5.15.210 with commit 4dd262f875e87653df50b138de1390ab0628e6b7
Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 6.1.176 with commit 6e4615164d185a26badb2f376a2449f4d174a5f0
Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 6.6.143 with commit 0f22412a2f4fbbe0251c132abee045d15a90e5b6
Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 6.12.94 with commit 0f7baa82a24813cdad0b06a6f8f07e4824af5ed5
Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 6.18.36 with commit dcf458120add64c96a6ef5cf719340453f6e6abf
Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 7.0.13 with commit 4fd34669558085bcb589aa2078a13b0ca79e360d
Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 7.1 with commit 34080db3e70ddf94c38512ad2331e3c3afca6cc1
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-52939
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
net/rds/ib_send.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/a0148342badd8c9b2e46551766a27cb76c82e715
https://git.kernel.org/stable/c/4dd262f875e87653df50b138de1390ab0628e6b7
https://git.kernel.org/stable/c/6e4615164d185a26badb2f376a2449f4d174a5f0
https://git.kernel.org/stable/c/0f22412a2f4fbbe0251c132abee045d15a90e5b6
https://git.kernel.org/stable/c/0f7baa82a24813cdad0b06a6f8f07e4824af5ed5
https://git.kernel.org/stable/c/dcf458120add64c96a6ef5cf719340453f6e6abf
https://git.kernel.org/stable/c/4fd34669558085bcb589aa2078a13b0ca79e360d
https://git.kernel.org/stable/c/34080db3e70ddf94c38512ad2331e3c3afca6cc1
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-06-24 7:16 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-24 7:13 CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion Greg Kroah-Hartman
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox