5.5
MEDIUM CVSS 3.1
CVE-2026-52939
net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
Description

In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion rds_ib_xmit_atomic() always programs a masked atomic opcode (IB_WR_MASKED_ATOMIC_CMP_AND_SWP or IB_WR_MASKED_ATOMIC_FETCH_AND_ADD) for every RDS atomic cmsg. But the completion-side switch in rds_ib_send_unmap_op() only handles the non-masked opcodes, so a masked atomic completion falls through to default and returns rm == NULL while send->s_op is left set. rds_ib_send_cqe_handler() then dereferences the NULL rm via rm->m_final_op, oopsing in softirq context. An unprivileged AF_RDS sendmsg() of an atomic cmsg over an active RDS/IB connection triggers it; on hardware that natively accepts masked atomics (mlx4, mlx5) no extra setup is needed. RDS/IB: rds_ib_send_unmap_op: unexpected opcode 0xd in WR! Oops: general protection fault [#1] SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000190-0x0000000000000197] RIP: rds_ib_send_cqe_handler+0x25c/0xb10 (net/rds/ib_send.c:282) Call Trace: <IRQ> rds_ib_send_cqe_handler (net/rds/ib_send.c:282) poll_scq (net/rds/ib_cm.c:274) rds_ib_tasklet_fn_send (net/rds/ib_cm.c:294) tasklet_action_common (kernel/softirq.c:943) handle_softirqs (kernel/softirq.c:573) run_ksoftirqd (kernel/softirq.c:479) </IRQ> Kernel panic - not syncing: Fatal exception in interrupt Handle the masked atomic opcodes in the same case as the non-masked ones: they map to the same struct rds_message.atomic union member, so the existing container_of()/rds_ib_send_unmap_atomic() body is correct for them.

INFO

Published Date :

June 24, 2026, 8:16 a.m.

Last Modified :

July 8, 2026, 7:14 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-52939 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 MEDIUM [email protected]
Solution
Fix NULL dereference in rds_ib_send_cqe_handler by handling masked atomic opcodes.
  • Update the Linux kernel to include the fix.
  • Ensure proper handling of masked atomic opcodes.
  • Apply the patch for rds_ib_send_cqe_handler.
  • Test the fix in softirq context.
Public PoC/Exploit Available at Github

CVE-2026-52939 has a 1 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-52939 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-52939 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

None

Python

Updated: 3 days, 19 hours ago
0 stars 0 fork 0 watcher
Born at : July 8, 2025, 4:34 a.m. This repo has been linked 79 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-52939 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-52939 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    Jul. 08, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
    Added CWE CWE-476
    Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.176 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.143 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.210 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 2.6.37 up to (excluding) 5.10.259 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.36 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.94 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.13 *cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/0f22412a2f4fbbe0251c132abee045d15a90e5b6 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/0f7baa82a24813cdad0b06a6f8f07e4824af5ed5 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/34080db3e70ddf94c38512ad2331e3c3afca6cc1 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/4dd262f875e87653df50b138de1390ab0628e6b7 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/4fd34669558085bcb589aa2078a13b0ca79e360d Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/6e4615164d185a26badb2f376a2449f4d174a5f0 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/a0148342badd8c9b2e46551766a27cb76c82e715 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/dcf458120add64c96a6ef5cf719340453f6e6abf Types: Patch
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 24, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': 'a0148342badd8c9b2e46551766a27cb76c82e715', 'versionType': 'git'}, {'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': '4dd262f875e87653df50b138de1390ab0628e6b7', 'versionType': 'git'}, {'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': '6e4615164d185a26badb2f376a2449f4d174a5f0', 'versionType': 'git'}, {'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': '0f22412a2f4fbbe0251c132abee045d15a90e5b6', 'versionType': 'git'}, {'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': '0f7baa82a24813cdad0b06a6f8f07e4824af5ed5', 'versionType': 'git'}, {'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': 'dcf458120add64c96a6ef5cf719340453f6e6abf', 'versionType': 'git'}, {'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': '4fd34669558085bcb589aa2078a13b0ca79e360d', 'versionType': 'git'}, {'status': 'affected', 'version': '20c72bd5f5f902e5a8745d51573699605bf8d21c', 'lessThan': '34080db3e70ddf94c38512ad2331e3c3afca6cc1', 'versionType': 'git'}], 'programFiles': ['net/rds/ib_send.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.37'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.37', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.259', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.210', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.176', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.143', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.94', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.36', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.13', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/rds/ib_send.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion rds_ib_xmit_atomic() always programs a masked atomic opcode (IB_WR_MASKED_ATOMIC_CMP_AND_SWP or IB_WR_MASKED_ATOMIC_FETCH_AND_ADD) for every RDS atomic cmsg. But the completion-side switch in rds_ib_send_unmap_op() only handles the non-masked opcodes, so a masked atomic completion falls through to default and returns rm == NULL while send->s_op is left set. rds_ib_send_cqe_handler() then dereferences the NULL rm via rm->m_final_op, oopsing in softirq context. An unprivileged AF_RDS sendmsg() of an atomic cmsg over an active RDS/IB connection triggers it; on hardware that natively accepts masked atomics (mlx4, mlx5) no extra setup is needed. RDS/IB: rds_ib_send_unmap_op: unexpected opcode 0xd in WR! Oops: general protection fault [#1] SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000190-0x0000000000000197] RIP: rds_ib_send_cqe_handler+0x25c/0xb10 (net/rds/ib_send.c:282) Call Trace: <IRQ> rds_ib_send_cqe_handler (net/rds/ib_send.c:282) poll_scq (net/rds/ib_cm.c:274) rds_ib_tasklet_fn_send (net/rds/ib_cm.c:294) tasklet_action_common (kernel/softirq.c:943) handle_softirqs (kernel/softirq.c:573) run_ksoftirqd (kernel/softirq.c:479) </IRQ> Kernel panic - not syncing: Fatal exception in interrupt Handle the masked atomic opcodes in the same case as the non-masked ones: they map to the same struct rds_message.atomic union member, so the existing container_of()/rds_ib_send_unmap_atomic() body is correct for them.
    Added Reference https://git.kernel.org/stable/c/0f22412a2f4fbbe0251c132abee045d15a90e5b6
    Added Reference https://git.kernel.org/stable/c/0f7baa82a24813cdad0b06a6f8f07e4824af5ed5
    Added Reference https://git.kernel.org/stable/c/34080db3e70ddf94c38512ad2331e3c3afca6cc1
    Added Reference https://git.kernel.org/stable/c/4dd262f875e87653df50b138de1390ab0628e6b7
    Added Reference https://git.kernel.org/stable/c/4fd34669558085bcb589aa2078a13b0ca79e360d
    Added Reference https://git.kernel.org/stable/c/6e4615164d185a26badb2f376a2449f4d174a5f0
    Added Reference https://git.kernel.org/stable/c/a0148342badd8c9b2e46551766a27cb76c82e715
    Added Reference https://git.kernel.org/stable/c/dcf458120add64c96a6ef5cf719340453f6e6abf
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.