CVE-2026-97954
CVE CVE-2026-97954EUVD EUVD-2026-86808Published 2026-09-25T10:23:01.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: net/rds: fix tcp stream corruption with large pages rds_message_map_pages() assigns PAGE_SIZE bytes to every scatterlist entry, even when total_len ends in a partial page. The RDS congestion map is defined as 8192 bytes, so on systems with PAGE_SIZE greater than 8192 the scatterlist maps bytes beyond the end of the congestion map. RDS-TCP transmits the SG contents according to those lengths, so the extra bytes become part of the TCP RDS stream and are interpreted as subsequent RDS message headers, corrupting the stream. Limit the final scatterlist mapping to the number of bytes remaining. This has no effect on systems with a 4K page size and allows RDS-TCP to be used on systems with 16K and larger page sizes. The RDS selftest, which previously hung on 16K pages, now passes.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 2.6.30; patch: 6.18.53; patch: 7.3-rc3; patch: 0; 7875e18e09961d29f30424c5e2e48e704dc3789b <8cbfeb54bf781d9693778aaba133bb58c0285332; 7875e18e09961d29f30424c5e2e48e704dc3789b <2ac09b5353fe6858411fdc8c6efa60d832e20f13; 7875e18e09961d29f30424c5e2e48e704dc3789b <f4649a716be20ef9272f97a166dea1825ba5b554; 7875e18e09961d29f30424c5e2e48e704dc3789b <ef3565a418b8309589fe9b5df098a892c9146b06; patch: 7.2.7; patch: 6.12.111
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.