SB20260406117 - Deadlock in Linux kernel rds
Published: April 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Deadlock (CVE-ID: CVE-2026-23419)
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a circular locking dependency in rds_tcp_tune when upgrading network reference counting while holding the socket lock. A local user can trigger the vulnerable code path to cause a denial of service.
The issue is caused by memory allocation occurring under the socket lock, creating a lock dependency with fs_reclaim in the Linux kernel RDS TCP code path.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/026bbaeeab9e04534ee58882b6447300629b42f6
- https://git.kernel.org/stable/c/6a877ececd6daa002a9a0002cd0fbca6592a9244
- https://git.kernel.org/stable/c/6ce948fa54599f369ff7fe8b793a6aae4b0762b2
- https://git.kernel.org/stable/c/8519e6883a942e510f33a0e634e27bcc3a844a40
- https://git.kernel.org/stable/c/8babb271403378ba6836f6c8599c5313d0e2355d