Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-52939

Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-476 Desreferencia a puntero nulo (NULL)
Fecha de publicación:
24/06/2026
Última modificación:
08/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion<br /> <br /> rds_ib_xmit_atomic() always programs a masked atomic opcode<br /> (IB_WR_MASKED_ATOMIC_CMP_AND_SWP or IB_WR_MASKED_ATOMIC_FETCH_AND_ADD)<br /> for every RDS atomic cmsg. But the completion-side switch in<br /> rds_ib_send_unmap_op() only handles the non-masked opcodes, so a masked<br /> atomic completion falls through to default and returns rm == NULL while<br /> send-&gt;s_op is left set. rds_ib_send_cqe_handler() then dereferences the<br /> NULL rm via rm-&gt;m_final_op, oopsing in softirq context. An unprivileged<br /> AF_RDS sendmsg() of an atomic cmsg over an active RDS/IB connection<br /> triggers it; on hardware that natively accepts masked atomics (mlx4,<br /> mlx5) no extra setup is needed.<br /> <br /> RDS/IB: rds_ib_send_unmap_op: unexpected opcode 0xd in WR!<br /> Oops: general protection fault [#1] SMP KASAN<br /> KASAN: null-ptr-deref in range [0x0000000000000190-0x0000000000000197]<br /> RIP: rds_ib_send_cqe_handler+0x25c/0xb10 (net/rds/ib_send.c:282)<br /> Call Trace:<br /> <br /> rds_ib_send_cqe_handler (net/rds/ib_send.c:282)<br /> poll_scq (net/rds/ib_cm.c:274)<br /> rds_ib_tasklet_fn_send (net/rds/ib_cm.c:294)<br /> tasklet_action_common (kernel/softirq.c:943)<br /> handle_softirqs (kernel/softirq.c:573)<br /> run_ksoftirqd (kernel/softirq.c:479)<br /> <br /> Kernel panic - not syncing: Fatal exception in interrupt<br /> <br /> Handle the masked atomic opcodes in the same case as the non-masked<br /> ones: they map to the same struct rds_message.atomic union member, so<br /> the existing container_of()/rds_ib_send_unmap_atomic() body is correct<br /> for them.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.37 (incluyendo) 5.10.259 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (incluyendo) 5.15.210 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (incluyendo) 6.1.176 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (incluyendo) 6.6.143 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.94 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.36 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.13 (excluyendo)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*