CVE-2026-52939 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion rds_ib_xmit_atomic() always programs a masked atomic opcode (IB_WR_MASKED_ATOMIC_CMP_AND_SWP or IB_WR_MASKED_ATOMIC_FETCH_AND_ADD) for every RDS atomic cmsg. But the completion-side switch in rds_ib_send_unmap_op() only handles the non-masked opcodes, so a masked atomic completion falls through to default and returns rm == NULL while send->s_op is left set. rds_ib_send_cqe_handler() then dereferences the NULL rm via rm->m_final_op, oopsing in softirq context. An unprivileged AF_RDS sendmsg() of an atomic cmsg over an active RDS/IB connection triggers it; on hardware that natively accepts masked atomics (mlx4, mlx5) no extra setup is needed. RDS/IB: rds_ib_send_unmap_op: unexpected opcode 0xd in WR! Oops: general protection fault [#1] SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000190-0x0000000000000197] RIP: rds_ib_send_cqe_handler+0x25c/0xb10 (net/rds/ib_send.c:282) Call Trace: <IRQ> rds_ib_send_cqe_handler (net/rds/ib_send.c:282) poll_scq (net/rds/ib_cm.c:274) rds_ib_tasklet_fn_send (net/rds/ib_cm.c:294) tasklet_action_common (kernel/softirq.c:943) handle_softirqs (kernel/softirq.c:573) run_ksoftirqd (kernel/softirq.c:479) </IRQ> Kernel panic - not syncing: Fatal exception in interrupt Handle the masked atomic opcodes in the same case as the non-masked ones: they map to the same struct rds_message.atomic union member, so the existing container_of()/rds_ib_send_unmap_atomic() body is correct for them.
A vulnerability in the Linux kernel's RDS (Reliable Datagram Sockets) implementation over InfiniBand can lead to a NULL pointer dereference. This issue occurs in the 'rds_ib_send_cqe_handler' function, specifically when handling masked atomic completion opcodes. The problem arises because the 'rds_ib_send_unmap_op' function does not properly manage these masked opcodes, causing the completion handler to dereference a NULL pointer. This vulnerability can be triggered by an unprivileged 'sendmsg' operation with an atomic control message over an active RDS/IB connection, particularly on hardware that supports masked atomic operations, such as Mellanox ConnectX-4 and ConnectX-5 adapters.
Users can upgrade to the patched version of the Linux kernel where this vulnerability has been addressed. The specific commit that fixes this issue is '34080db3e70ddf94c38512ad2331e3c3afca6cc1', which is available in the Linux kernel stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0f22412a2f4fbbe0251c132abee045d15a90e5b6 | kernel.org | Patch |
| https://git.kernel.org/stable/c/0f7baa82a24813cdad0b06a6f8f07e4824af5ed5 | kernel.org | Patch |
| https://git.kernel.org/stable/c/34080db3e70ddf94c38512ad2331e3c3afca6cc1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4dd262f875e87653df50b138de1390ab0628e6b7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4fd34669558085bcb589aa2078a13b0ca79e360d | kernel.org | Patch |
| https://git.kernel.org/stable/c/6e4615164d185a26badb2f376a2449f4d174a5f0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a0148342badd8c9b2e46551766a27cb76c82e715 | kernel.org | Patch |
| https://git.kernel.org/stable/c/dcf458120add64c96a6ef5cf719340453f6e6abf | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.37, < 5.10.259 >= 5.11, < 5.15.210 >= 5.16, < 6.1.176 >= 6.2, < 6.6.143 >= 6.7, < 6.12.94 >= 6.13, < 6.18.36 >= 6.19, < 7.0.13 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 7.1 rc5 7.1 rc6 7.1 rc7 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | Initial Analysis | [email protected] |
| Jun 24, 2026 | New CVE Received | kernel.org |