net/rds: reset op_nents when zerocopy page pin fails
When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(),
the pinned pages are released with put_page(), and
rm->data.op_mmp_znotifier is cleared. But we fail to properly
clear rm->data.op_nents.
Later when rds_message_purge() is called from rds_sendmsg() the
cleanup loop iterates over the incorrectly non zero number of
op_nents and frees them again.
Fix this by properly resetting op_nents when it should be in
rds_message_zcopy_from_user().
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6305-1 | linux security update |
Ubuntu USN |
USN-8370-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-8371-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-8373-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-8374-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-8426-1 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-8426-2 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-8440-1 | Linux kernel (Azure) vulnerabilities |
Fri, 12 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 01 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 30 May 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Sat, 23 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 22 May 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-416 CWE-795 |
Fri, 22 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1341 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 21 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 21 May 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-416 CWE-795 |
Thu, 21 May 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinned pages are released with put_page(), and rm->data.op_mmp_znotifier is cleared. But we fail to properly clear rm->data.op_nents. Later when rds_message_purge() is called from rds_sendmsg() the cleanup loop iterates over the incorrectly non zero number of op_nents and frees them again. Fix this by properly resetting op_nents when it should be in rds_message_zcopy_from_user(). | |
| Title | net/rds: reset op_nents when zerocopy page pin fails | |
| First Time appeared |
Linux
Linux linux Kernel |
|
| CPEs | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Linux
Linux linux Kernel |
|
| References |
|
Status: PUBLISHED
Assigner: Linux
Published:
Updated: 2026-06-14T17:45:20.190Z
Reserved: 2026-05-01T14:12:56.013Z
Link: CVE-2026-43494
No data.
Status : Awaiting Analysis
Published: 2026-05-21T12:16:19.957
Modified: 2026-06-17T10:49:48.710
Link: CVE-2026-43494
OpenCVE Enrichment
Updated: 2026-05-30T13:15:24Z
Debian DSA
Ubuntu USN