CVE-2026-90081

Source
https://cve.org/CVERecord?id=CVE-2026-90081
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90081.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90081
Downstream
Published
2026-09-17T16:05:58Z
Modified
2026-09-19T03:47:23Z
Summary
net/rds: use wq_has_sleeper() in rds_cong_map_updated()
Details

In the Linux kernel, the following vulnerability has been resolved:

net/rds: use wq_has_sleeper() in rds_cong_map_updated()

rds_cong_map_updated() runs after a peer's congestion map has been rewritten (by rds_tcp_cong_recv() and rds_ib_cong_recv(), or the clear-all in the loopback and IB send-completion paths). It bumps rds_cong_generation and then checks waitqueue_active() on map->m_waitq and on rds_poll_waitq to decide whether anyone needs waking. atomic_inc() carries no ordering and waitqueue_active() is a plain load, so nothing orders the map and generation stores before the wait queue reads. The waiters do the mirror image: rds_cong_wait() adds itself to m_waitq and then tests the port bit, and rds_poll() registers on rds_poll_waitq and then reads the generation. That is the store-buffering pattern described above waitqueue_active() in include/linux/wait.h - the updater can observe an empty wait queue while the waiter still observes the port as congested, and no wake-up is issued.

rds_cong_wait() is an interruptible sleep with no timeout, so a sender blocked on a congested port stays blocked until the next congestion update from that peer arrives or a signal is delivered. A poll() waiter misses the map-updated notification the same way.

Use wq_has_sleeper(), which is waitqueue_active() preceded by the required full barrier, as rds_tcp_state_change() already does for the same pattern.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90081.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
922cb17a5c812fcc9ebee249f4109db099896941
Fixed
2a809d7896dbf18e1ecfbdd930f71c9fc298b16d
Fixed
fa4b98e891fda28cc0638d809c6125ec63d8319d
Fixed
0e169f6a2adeb17b5577ed7e8abd642465bb50ec
Fixed
42884bd8b8fd023d6a610a695bd5ddd1d5dece17
Fixed
a526214b9f0548ca0e53a6e0d1727d8ea9befc23
Fixed
bf2b8130723efcb5b86c3ddb6317c3a9b2a9cfc5
Fixed
281f9fda2e06d6c211bb365a5379ed2e05cc2e21
Fixed
d4f484661961636eb90d287050959e613795f73a

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90081.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.30
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90081.json"