From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 100B038D01E for ; Wed, 24 Jun 2026 07:16:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782285389; cv=none; b=fkGWJyy8TSgH10MLL8PIHyf6lu/VIEZEUYBR/sYx+6Iq8/+/5lb6qU0d80Zk5NV1ObP+BxHTd2qHlEDKialYZEmuxz88j1t/z4Y1rtFlLfY2ZDal3GI0UTe+ebBHhdPxK0GVL4fTK/fg9o7CdoUueaWduYq2LESAyG4yxrCbPgQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782285389; c=relaxed/simple; bh=qKmRe4MP3KmNHhVv5EjXTEb41IK1CZs2c5FHGcUC2WA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=qfQ6rnUM5eB9DrzPVmSnTM1bkfJYo7eX1TU5VqgmeKB3EUg80p/TI0z3yT9XL6+39L9Q3DHScIHicPRFvtyVLieZwigBvmtn4Xh6jHtSV8pR/DLTvH8eIgc46uxp9gPxAyT/EpO+7nA5jRDQqAVje1WZTywjniy2jCjGTQo5TFY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=liXdnloM; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="liXdnloM" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 543C21F000E9; Wed, 24 Jun 2026 07:16:27 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1782285388; bh=wa4BbAH+vmosLnxK5+PARKWDFsGeOLPrjTnIPZRxMVs=; h=From:To:Cc:Subject:Date:Reply-To; b=liXdnloMFjpK4pgh8mhwU9DcT5+5M9yfEXFG/qnuH25kJ6OByA7GHaQJ8TzhV1P5M Re2ZmCUJSkRlu+EFzoYPhCqvNonElhuD0zRd1WmFTLpVnS8AhRtyYz1D0crz5kcB48 gowhNtU8buZszl5MX8TEwRr8h9M8rZAOhglKe4gA= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion Date: Wed, 24 Jun 2026 09:13:54 +0200 Message-ID: <2026062434-CVE-2026-52939-b7cd@gregkh> X-Mailer: git-send-email 2.54.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4677; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=7L4ldFnWHSSE6KPVp5KS+vo/qqoKu8r6Fvq5kqPjeLo=; b=owGbwMvMwCRo6H6F97bub03G02pJDFnWzfNyt1mec1AL8XU6wsWUea9v5c37d/iuV7CWTBLzK PpzIu58RywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAEzkTTrDgkv/pvwru1fE7mYy /WqMmc8Sbss/PQzzIycF/rr7ua6hIKhT3k2I7/XRlUuWAQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion rds_ib_xmit_atomic() always programs a masked atomic opcode (IB_WR_MASKED_ATOMIC_CMP_AND_SWP or IB_WR_MASKED_ATOMIC_FETCH_AND_ADD) for every RDS atomic cmsg. But the completion-side switch in rds_ib_send_unmap_op() only handles the non-masked opcodes, so a masked atomic completion falls through to default and returns rm == NULL while send->s_op is left set. rds_ib_send_cqe_handler() then dereferences the NULL rm via rm->m_final_op, oopsing in softirq context. An unprivileged AF_RDS sendmsg() of an atomic cmsg over an active RDS/IB connection triggers it; on hardware that natively accepts masked atomics (mlx4, mlx5) no extra setup is needed. RDS/IB: rds_ib_send_unmap_op: unexpected opcode 0xd in WR! Oops: general protection fault [#1] SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000190-0x0000000000000197] RIP: rds_ib_send_cqe_handler+0x25c/0xb10 (net/rds/ib_send.c:282) Call Trace: rds_ib_send_cqe_handler (net/rds/ib_send.c:282) poll_scq (net/rds/ib_cm.c:274) rds_ib_tasklet_fn_send (net/rds/ib_cm.c:294) tasklet_action_common (kernel/softirq.c:943) handle_softirqs (kernel/softirq.c:573) run_ksoftirqd (kernel/softirq.c:479) Kernel panic - not syncing: Fatal exception in interrupt Handle the masked atomic opcodes in the same case as the non-masked ones: they map to the same struct rds_message.atomic union member, so the existing container_of()/rds_ib_send_unmap_atomic() body is correct for them. The Linux kernel CVE team has assigned CVE-2026-52939 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 5.10.259 with commit a0148342badd8c9b2e46551766a27cb76c82e715 Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 5.15.210 with commit 4dd262f875e87653df50b138de1390ab0628e6b7 Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 6.1.176 with commit 6e4615164d185a26badb2f376a2449f4d174a5f0 Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 6.6.143 with commit 0f22412a2f4fbbe0251c132abee045d15a90e5b6 Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 6.12.94 with commit 0f7baa82a24813cdad0b06a6f8f07e4824af5ed5 Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 6.18.36 with commit dcf458120add64c96a6ef5cf719340453f6e6abf Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 7.0.13 with commit 4fd34669558085bcb589aa2078a13b0ca79e360d Issue introduced in 2.6.37 with commit 20c72bd5f5f902e5a8745d51573699605bf8d21c and fixed in 7.1 with commit 34080db3e70ddf94c38512ad2331e3c3afca6cc1 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-52939 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/rds/ib_send.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/a0148342badd8c9b2e46551766a27cb76c82e715 https://git.kernel.org/stable/c/4dd262f875e87653df50b138de1390ab0628e6b7 https://git.kernel.org/stable/c/6e4615164d185a26badb2f376a2449f4d174a5f0 https://git.kernel.org/stable/c/0f22412a2f4fbbe0251c132abee045d15a90e5b6 https://git.kernel.org/stable/c/0f7baa82a24813cdad0b06a6f8f07e4824af5ed5 https://git.kernel.org/stable/c/dcf458120add64c96a6ef5cf719340453f6e6abf https://git.kernel.org/stable/c/4fd34669558085bcb589aa2078a13b0ca79e360d https://git.kernel.org/stable/c/34080db3e70ddf94c38512ad2331e3c3afca6cc1