CVE-2026-52939
net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
Description
In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion rds_ib_xmit_atomic() always programs a masked atomic opcode (IB_WR_MASKED_ATOMIC_CMP_AND_SWP or IB_WR_MASKED_ATOMIC_FETCH_AND_ADD) for every RDS atomic cmsg. But the completion-side switch in rds_ib_send_unmap_op() only handles the non-masked opcodes, so a masked atomic completion falls through to default and returns rm == NULL while send->s_op is left set. rds_ib_send_cqe_handler() then dereferences the NULL rm via rm->m_final_op, oopsing in softirq context. An unprivileged AF_RDS sendmsg() of an atomic cmsg over an active RDS/IB connection triggers it; on hardware that natively accepts masked atomics (mlx4, mlx5) no extra setup is needed. RDS/IB: rds_ib_send_unmap_op: unexpected opcode 0xd in WR! Oops: general protection fault [#1] SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000190-0x0000000000000197] RIP: rds_ib_send_cqe_handler+0x25c/0xb10 (net/rds/ib_send.c:282) Call Trace: <IRQ> rds_ib_send_cqe_handler (net/rds/ib_send.c:282) poll_scq (net/rds/ib_cm.c:274) rds_ib_tasklet_fn_send (net/rds/ib_cm.c:294) tasklet_action_common (kernel/softirq.c:943) handle_softirqs (kernel/softirq.c:573) run_ksoftirqd (kernel/softirq.c:479) </IRQ> Kernel panic - not syncing: Fatal exception in interrupt Handle the masked atomic opcodes in the same case as the non-masked ones: they map to the same struct rds_message.atomic union member, so the existing container_of()/rds_ib_send_unmap_atomic() body is correct for them.
INFO
Published Date :
June 24, 2026, 8:16 a.m.
Last Modified :
July 8, 2026, 7:14 p.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | MEDIUM | [email protected] |
Solution
- Update the Linux kernel to include the fix.
- Ensure proper handling of masked atomic opcodes.
- Apply the patch for rds_ib_send_cqe_handler.
- Test the fix in softirq context.
Public PoC/Exploit Available at Github
CVE-2026-52939 has a 1 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-52939.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-52939 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-52939
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
None
Python
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-52939 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-52939 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Initial Analysis by [email protected]
Jul. 08, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Added CWE CWE-476 Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.176 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.143 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.210 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 2.6.37 up to (excluding) 5.10.259 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.36 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.94 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.13 *cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:* Added Reference Type kernel.org: https://git.kernel.org/stable/c/0f22412a2f4fbbe0251c132abee045d15a90e5b6 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/0f7baa82a24813cdad0b06a6f8f07e4824af5ed5 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/34080db3e70ddf94c38512ad2331e3c3afca6cc1 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/4dd262f875e87653df50b138de1390ab0628e6b7 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/4fd34669558085bcb589aa2078a13b0ca79e360d Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/6e4615164d185a26badb2f376a2449f4d174a5f0 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/a0148342badd8c9b2e46551766a27cb76c82e715 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/dcf458120add64c96a6ef5cf719340453f6e6abf Types: Patch -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 24, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': 'a0148342badd8c9b2e46551766a27cb76c82e715', 'versionType': 'git'}, {'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': '4dd262f875e87653df50b138de1390ab0628e6b7', 'versionType': 'git'}, {'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': '6e4615164d185a26badb2f376a2449f4d174a5f0', 'versionType': 'git'}, {'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': '0f22412a2f4fbbe0251c132abee045d15a90e5b6', 'versionType': 'git'}, {'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': '0f7baa82a24813cdad0b06a6f8f07e4824af5ed5', 'versionType': 'git'}, {'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': 'dcf458120add64c96a6ef5cf719340453f6e6abf', 'versionType': 'git'}, {'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': '4fd34669558085bcb589aa2078a13b0ca79e360d', 'versionType': 'git'}, {'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': '34080db3e70ddf94c38512ad2331e3c3afca6cc1', 'versionType': 'git'}], 'programFiles': ['net/rds/ib_send.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.37'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.37', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.259', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.210', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.176', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.143', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.94', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.36', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.13', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/rds/ib_send.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion rds_ib_xmit_atomic() always programs a masked atomic opcode (IB_WR_MASKED_ATOMIC_CMP_AND_SWP or IB_WR_MASKED_ATOMIC_FETCH_AND_ADD) for every RDS atomic cmsg. But the completion-side switch in rds_ib_send_unmap_op() only handles the non-masked opcodes, so a masked atomic completion falls through to default and returns rm == NULL while send->s_op is left set. rds_ib_send_cqe_handler() then dereferences the NULL rm via rm->m_final_op, oopsing in softirq context. An unprivileged AF_RDS sendmsg() of an atomic cmsg over an active RDS/IB connection triggers it; on hardware that natively accepts masked atomics (mlx4, mlx5) no extra setup is needed. RDS/IB: rds_ib_send_unmap_op: unexpected opcode 0xd in WR! Oops: general protection fault [#1] SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000190-0x0000000000000197] RIP: rds_ib_send_cqe_handler+0x25c/0xb10 (net/rds/ib_send.c:282) Call Trace: <IRQ> rds_ib_send_cqe_handler (net/rds/ib_send.c:282) poll_scq (net/rds/ib_cm.c:274) rds_ib_tasklet_fn_send (net/rds/ib_cm.c:294) tasklet_action_common (kernel/softirq.c:943) handle_softirqs (kernel/softirq.c:573) run_ksoftirqd (kernel/softirq.c:479) </IRQ> Kernel panic - not syncing: Fatal exception in interrupt Handle the masked atomic opcodes in the same case as the non-masked ones: they map to the same struct rds_message.atomic union member, so the existing container_of()/rds_ib_send_unmap_atomic() body is correct for them. Added Reference https://git.kernel.org/stable/c/0f22412a2f4fbbe0251c132abee045d15a90e5b6 Added Reference https://git.kernel.org/stable/c/0f7baa82a24813cdad0b06a6f8f07e4824af5ed5 Added Reference https://git.kernel.org/stable/c/34080db3e70ddf94c38512ad2331e3c3afca6cc1 Added Reference https://git.kernel.org/stable/c/4dd262f875e87653df50b138de1390ab0628e6b7 Added Reference https://git.kernel.org/stable/c/4fd34669558085bcb589aa2078a13b0ca79e360d Added Reference https://git.kernel.org/stable/c/6e4615164d185a26badb2f376a2449f4d174a5f0 Added Reference https://git.kernel.org/stable/c/a0148342badd8c9b2e46551766a27cb76c82e715 Added Reference https://git.kernel.org/stable/c/dcf458120add64c96a6ef5cf719340453f6e6abf