Answer in brief
CVE-2026-98257 records a Unknown severity vulnerability in rds: ib: use rds_conn_drop() on protocol version mismatch. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f147dd9ecabf23fd63d2562ffe64252a0453ecde <424019be3f637da76b74f44a40034669acbb166f || >=f147dd9ecabf23fd63d2562ffe64252a0453ecde <14fb90067d13f4494cff0f03243fae3cf2911cbc || >=f147dd9ecabf23fd63d2562ffe64252a0453ecde <344c72a0bc2703a6de4918ed935850e07dae3af2 || >=f147dd9ecabf23fd63d2562ffe64252a0453ecde <b5c9f2951d330d4a198a64d6e60f79b4bd6ef078 || >=f147dd9ecabf23fd63d2562ffe64252a0453ecde <d392b16acd0908f077289aad8bba066ff16de336 || >=f147dd9ecabf23fd63d2562ffe64252a0453ecde <65ca0a5037152a5a80b8fe6aac80eb80458be573 || >=f147dd9ecabf23fd63d2562ffe64252a0453ecde <7d8c22cb2cb1efb5e830a4545c76abf7b35cc2e8 || >=f147dd9ecabf23fd63d2562ffe64252a0453ecde <f97d8c7bab7843631206a114986c9059da03efeb | 424019be3f637da76b74f44a40034669acbb166f, 14fb90067d13f4494cff0f03243fae3cf2911cbc, 344c72a0bc2703a6de4918ed935850e07dae3af2, b5c9f2951d330d4a198a64d6e60f79b4bd6ef078, d392b16acd0908f077289aad8bba066ff16de336, 65ca0a5037152a5a80b8fe6aac80eb80458be573, 7d8c22cb2cb1efb5e830a4545c76abf7b35cc2e8, f97d8c7bab7843631206a114986c9059da03efeb |
| Linux/Linuxgeneric | 2.6.37 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: rds: ib: use rds_conn_drop() on protocol version mismatch rds_ib_cm_connect_complete() runs from the RDMA-CM event handler with conn->c_cm_lock held. When the peer negotiates a protocol version older than RDS_PROTOCOL_COMPAT_VERSION, the handler calls rds_conn_destroy(), which is only safe in the rmmod path: it synchronously tears the connection down and flush_work()es the shutdown work cp_down_w. That shutdown work (rds_conn_shutdown()) needs cp_cm_lock, which is the very lock the event handler still holds, so the flush never completes: the two workers wait on each other and the RDS connection workqueues stall for good. All other RDMA-CM failure paths (REJECTED, CONNECT_ERROR, DISCONNECTED) use rds_conn_drop(), which marks the connection RDS_CONN_ERROR and schedules the shutdown work asynchronously. Use it here as well.
Quoted source text, attributed separately from HOL analysis.