RDS Fastpath Lock Vulnerability in Linux Kernel Affecting Multiple Releases
CVE-2026-98069

8.1HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98069?

The RDS (Reliable Datagram Sockets) implementation in the Linux kernel contains a vulnerability that arises during the connection shutdown process. Specifically, the method responsible for shutting down the connection may inadvertently allow concurrent execution of the transmit and receive paths due to insufficient locking mechanisms. When the connection is terminated, the system is designed to quiesce both transmit and reception activities by clearing specific bits. However, these bits can be reacquired during the shutdown process, leading to a potential race condition that compromises network stability. The recent fix ensures that both aspects of the connection teardown properly acquire necessary locks, maintaining order and preventing conflicting access during critical operations.

Affected Version(s)

Linux 0f4b1c7e89e699f588807a914ec6e6396c851a72 < 7f4f21e4439df30d9aca9fb3bac38191a2f34729

Linux 0f4b1c7e89e699f588807a914ec6e6396c851a72 < 1f900f585cbb0fbe6aa00c31c9f5bb63ee614456

Linux 0f4b1c7e89e699f588807a914ec6e6396c851a72 < 32e21bcf4b5b11454bf57c4bb3bf019b71512ace

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.