Executive brief
A vulnerability in the Linux kernel's Reliable Datagram Sockets (RDS) protocol could allow a local user to cause a system crash. The issue occurs when the system fails to properly track memory pages during high-performance data transfers, leading to a 'double free' error where the system tries to release the same memory twice. This can result in a kernel panic, disrupting services and impacting system availability.
Technical details
A double-free vulnerability exists in net/rds/message.c within the Linux kernel. When iov_iter_get_pages2() fails during a zerocopy transfer in rds_message_zcopy_from_user(), the code releases pinned pages but fails to reset the 'op_nents' counter to zero. Consequently, when rds_message_purge() is subsequently called via rds_sendmsg(), the kernel attempts to iterate over and free the same pages again based on the stale 'op_nents' value. This flaw can be triggered by a local attacker to cause a kernel NULL pointer dereference or general protection fault, leading to a Denial of Service (DoS). A patch has been released to ensure 'op_nents' is properly reset upon failure.
Affected products
- Linux Linux Kernel All versions including and prior to 6.x (fixed in 2026)
Timeline
- 2026-05-05: patched: Fix committed to mainline kernel tree.
- 2026-05-21: disclosed: CVE published in NVD.