{"id":"AZL-106431","summary":"CVE-2026-98257 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nrds: ib: use rds_conn_drop() on protocol version mismatch\n\nrds_ib_cm_connect_complete() runs from the RDMA-CM event handler with\nconn-\u003ec_cm_lock held.  When the peer negotiates a protocol version\nolder than RDS_PROTOCOL_COMPAT_VERSION, the handler calls\nrds_conn_destroy(), which is only safe in the rmmod path: it\nsynchronously tears the connection down and flush_work()es the\nshutdown work cp_down_w.\n\nThat shutdown work (rds_conn_shutdown()) needs cp_cm_lock, which is\nthe very lock the event handler still holds, so the flush never\ncompletes: the two workers wait on each other and the RDS connection\nworkqueues stall for good.\n\nAll other RDMA-CM failure paths (REJECTED, CONNECT_ERROR,\nDISCONNECTED) use rds_conn_drop(), which marks the connection\nRDS_CONN_ERROR and schedules the shutdown work asynchronously.  Use\nit here as well.","modified":"2026-10-07T14:17:03.287206399Z","published":"2026-10-06T09:18:14Z","upstream":["CVE-2026-98257"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98257"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106431.json"}}],"schema_version":"1.9.0"}