[CVE-2026-43494][IMPORTANT] net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinned pages are released with put_page(), and rm->data.op_mmp_znotifier is cleared. But we fail to properly clear rm->data.op_nents. Later when rds_message_purge() is called from rds_sendmsg() the cleanup loop iterates over the incorrectly non zero number of op_nents and frees them again. Fix this by properly resetting op_nents when it should be in rds_message_zcopy_from_user(). Fixes: 0cebacc ("rds: zerocopy Tx support.") Signed-off-by: Allison Henderson <[email protected]> Reviewed-by: Simon Horman <[email protected]> Link: https://patch.msgid.link/[email protected] Signed-off-by: Jakub Kicinski <[email protected]>
2026-05-21 14:52 UTC
[CVE-2026-43496][LOW] net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked
2026-05-21 12:57 UTC
[CVE-2026-43501][IMPORTANT] ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
2026-05-21 12:52 UTC
[CVE-2026-43330][MODERATE REGULAR] crypto: caam - fix overflow on long hmac keys [ Upstream
2026-05-21 11:25 UTC
[CVE-2026-43023][IMPORTANT] Bluetooth: SCO: fix race conditions in sco_sock_connect() [ Upstream
2026-05-21 4:38 UTC
[CVE-2026-43037][IMPORTANT] ip6_tunnel: clear skb2->cb[] in ip4ip6_err() [ Upstream
2026-05-21 4:28 UTC
[CVE-2024-39503][MODERATE 7.0] netfilter: ipset: Fix race between namespace cleanup and gc in the list:set type [ Upstream
2026-05-21 3:35 UTC
[CVE-2026-43038][IMPORTANT] ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() [ Upstream
2026-05-21 2:42 UTC
[CVE-2022-50835][LOW] jbd2: add miss release buffer head in fc_do_one_pass()
2026-05-21 2:38 UTC
[CVE-2026-31431][IMPORTANT] crypto: algif_aead - Revert to operating out-of-place [ Upstream
2026-05-21 2:22 UTC
[CVE-2026-43500][IMPORTANT] rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
2026-05-21 1:43 UTC
[CVE-2026-43304][IMPORTANT] libceph: define and enforce CEPH_MAX_KEY_LEN [ Upstream
2026-05-20 23:59 UTC
[CVE-2026-43208][MODERATE 7.0] net: do not pass flow_id to set_rps_cpu() [ Upstream
2026-05-20 21:36 UTC
page: | prev (newer) | latest
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox