Race condition in Linux kernel - CVE-2026-98068
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in RDS TCP connection path shutdown handling when connection teardown races with acceptance of a new socket. A remote attacker can trigger concurrent connection teardown and socket acceptance to cause a denial of service.
The affected path can remain in RDS_CONN_DOWN with an established socket and a growing receive queue.