Improper control of a resource through its lifetime in Linux kernel - CVE-2026-43230
Published: May 7, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the reconnect worker handling in net/rds when canceling the reconnect worker before it is scheduled. A local user can trigger cancellation of the reconnect worker in that state to cause a denial of service.
The reconnect-pending bit may remain set indefinitely if the worker is canceled before being scheduled.
Remediation
External links
- https://git.kernel.org/stable/c/14eae5564053ac3973b9369dc674638f22f4765e
- https://git.kernel.org/stable/c/391200c274e90c34071b909ba12e3390b81b767f
- https://git.kernel.org/stable/c/3cf001aff71b1db1b4732a5381b012a114720664
- https://git.kernel.org/stable/c/597c46a42930c963f448720aaf5001dd4ed98af4
- https://git.kernel.org/stable/c/60b347333ec259ac7352f62cbbc365b04c065ff8
- https://git.kernel.org/stable/c/b89fc7c2523b2b0750d91840f4e52521270d70ed
- https://git.kernel.org/stable/c/ba2e3472022f44baddf000621fed150d7a599ea3
- https://git.kernel.org/stable/c/bcf034fa5f66b6a3e787f765a917934a2045cf7a