Junglewise Threat Intelligence

CVE-2026-64281: Linux Kernel resource exhaustion in svcrdma transport close

CVE-2026-64281 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's RDMA (Remote Direct Memory Access) transport layer can cause system threads to hang indefinitely when a connection is closed. This occurs because certain background processes fail to receive a 'wake up' signal during transport teardown, leading to a state where system resources cannot be freed. In practice, this can lead to a denial-of-service condition where the server becomes unresponsive or unable to properly manage network connections.

Technical details

A race condition or logic error in the Linux kernel's svcrdma implementation causes threads parked in svc_rdma_sq_wait() on sc_sq_ticket_wait or sc_send_wait to remain in a TASK_UNINTERRUPTIBLE state during transport teardown. While the close path sets the XPT_CLOSE flag, the wait_event predicates are only re-evaluated upon a wakeup signal, which is missing in certain teardown paths (such as remote disconnects handled by svc_rdma_cma_handler). This results in threads pinning svc_xprt references indefinitely, blocking svc_rdma_free() and preventing the transport from being decommissioned. The fix introduces svc_rdma_xprt_deferred_close() to ensure explicit wakeups are sent to both waitqueues during deferred and synchronous close operations.

Affected products

  • Linux Linux Kernel ccc89b9d1ed2 to 40eedc4253db

Timeline

  • 2026-05-22: other: Patch authored
  • 2026-07-25: advisory: CVE-2026-64281 published

References

Related threats