Linux Kernel Vulnerability in RDS Transmit Path Management
CVE-2026-98070

8.1HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98070?

A vulnerability in the Linux kernel affecting the Reliable Datagram Sockets (RDS) protocol has been identified. The issue arises in the way the transmit path manages state during socket resets. Specifically, the function rds_tcp_reset_callbacks() improperly handles the quiescing of the transmit path, which could lead to race conditions between different processes. When the transmit state is changed, there is a risk that the state might be in flux, allowing for concurrent processes to interfere with each other’s operations, potentially leading to data corruption or transmission errors. The fix involves implementing proper locking mechanisms during the socket swap process to ensure that all operations are serialized correctly, preventing these harmful interactions and maintaining data integrity.

Affected Version(s)

Linux 335b48d980f631fbc5b233cbb3625ac0c86d67cb < 670af4e4a4de5e6bb5daee3838485571a0caa5fa

Linux 335b48d980f631fbc5b233cbb3625ac0c86d67cb < 830a2e21b200c6b6fdccc63dd3f23932bf7a894b

Linux 335b48d980f631fbc5b233cbb3625ac0c86d67cb

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.