CVE-2026-43226 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net/rds: No shortcut out of RDS_CONN_ERROR RDS connections carry a state "rds_conn_path::cp_state" and transitions from one state to another and are conditional upon an expected state: "rds_conn_path_transition." There is one exception to this conditionality, which is "RDS_CONN_ERROR" that can be enforced by "rds_conn_path_drop" regardless of what state the condition is currently in. But as soon as a connection enters state "RDS_CONN_ERROR", the connection handling code expects it to go through the shutdown-path. The RDS/TCP multipath changes added a shortcut out of "RDS_CONN_ERROR" straight back to "RDS_CONN_CONNECTING" via "rds_tcp_accept_one_path" (e.g. after "rds_tcp_state_change"). A subsequent "rds_tcp_reset_callbacks" can then transition the state to "RDS_CONN_RESETTING" with a shutdown-worker queued. That'll trip up "rds_conn_init_shutdown", which was never adjusted to handle "RDS_CONN_RESETTING" and subsequently drops the connection with the dreaded "DR_INV_CONN_STATE", which leaves "RDS_SHUTDOWN_WORK_QUEUED" on forever. So we do two things here: a) Don't shortcut "RDS_CONN_ERROR", but take the longer path through the shutdown code. b) Add "RDS_CONN_RESETTING" to the expected states in "rds_conn_init_shutdown" so that we won't error out and get stuck, if we ever hit weird state transitions like this again."
A vulnerability in the Linux kernel's Reliable Datagram Sockets (RDS) implementation has been addressed. This issue arises from improper handling of connection states, particularly the 'RDS_CONN_ERROR' state. When a connection enters this state, it is expected to follow a shutdown process. However, recent changes to the RDS over TCP multipath handling introduced a shortcut that bypasses this requirement, allowing connections to improperly transition back to an active state. This can lead to a situation where the connection management code encounters an unexpected state, causing it to erroneously drop the connection and leave certain shutdown processes uncompleted, potentially leading to resource leaks.
The vulnerability has been fixed in the Linux kernel stable releases. Users should upgrade to the latest version of the Linux kernel to apply this fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/19e384a7d00d888303a8285977cdf1970c6cccd6 | kernel.org | Patch |
| https://git.kernel.org/stable/c/81248b1eb3c5954cc1fc7b33b7c03e34d20cb8c8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/899ef00963ce76f9fc421a7d02335fe4ead6389b | kernel.org | Patch |
| https://git.kernel.org/stable/c/9bcd7c00691a2db9745817d5ea79262a503b135c | kernel.org | Patch |
| https://git.kernel.org/stable/c/9ff599a9be784a808c36765086e3db2144aa3b66 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a179ac7be8f5a650d0068040705f4cddd6ca369c | kernel.org | Patch |
| https://git.kernel.org/stable/c/ad22d24be635c6beab6a1fdd3f8b1f3c478d15da | kernel.org | Patch |
| https://git.kernel.org/stable/c/f0f729bdffb08af32e0f54521b81b8a9e0321f16 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.8, < 5.10.252 >= 5.11, < 5.15.202 >= 5.16, < 6.1.165 >= 6.2, < 6.6.128 >= 6.7, < 6.12.75 >= 6.13, < 6.18.16 >= 6.19, < 6.19.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 8, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | CVE Modified | kernel.org |
| May 6, 2026 | New CVE Received | kernel.org |