← Πίσω στην αναζήτηση CVE

CVE-2026-43226

Linux Kernel

Περιγραφή

In the Linux kernel, the following vulnerability has been resolved: net/rds: No shortcut out of RDS_CONN_ERROR RDS connections carry a state -rds_conn_path::cp_state- and transitions from one state to another and are conditional upon an expected state: -rds_conn_path_transition.- There is one exception to this conditionality, which is -RDS_CONN_ERROR- that can be enforced by -rds_conn_path_drop- regardless of what state the condition is currently in. But as soon as a connection enters state -RDS_CONN_ERROR-, the connection handling code expects it to go through the shutdown-path. The RDS/TCP multipath changes added a shortcut out of -RDS_CONN_ERROR- straight back to -RDS_CONN_CONNECTING- via -rds_tcp_accept_one_path- (e.g. after -rds_tcp_state_change-). A subsequent -rds_tcp_reset_callbacks- can then transition the state to -RDS_CONN_RESETTING- with a shutdown-worker queued. That-ll trip up -rds_conn_init_shutdown-, which was never adjusted to handle -RDS_CONN_RESETTING- and subsequent...

CVSS 7.5EPSS 0.523%Κίνδυνος 0.79
Προβολή πηγής
Δημοσίευση
2026-05-06 12:16:42
Επηρεαζόμενες εκδόσεις
unknown
Τύπος
Core software
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Λειτουργικά συστήματα
Linux