PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-52939 Linux CVE debrief

A vulnerability in the Linux kernel's RDS/IB (Remote Direct Memory Access over InfiniBand) implementation could allow an unprivileged user to trigger a NULL pointer dereference. The issue arises from the handling of masked atomic completions in the rds_ib_send_cqe_handler() function. When a masked atomic opcode is used, the function does not properly handle it, leading to a NULL pointer dereference. This vulnerability can be triggered by sending an atomic cmsg over an active RDS/IB connection using the AF_RDS socket.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-24
Original CVE updated
2026-07-08
Advisory published
2026-06-24
Advisory updated
2026-07-08

Who should care

System administrators and users of Linux-based systems, particularly those using RDS/IB, should be aware of this vulnerability. An unprivileged user could potentially exploit this vulnerability to cause a denial-of-service (DoS) or possibly execute arbitrary code with elevated privileges.

Technical summary

The vulnerability is caused by the rds_ib_send_unmap_op() function not handling masked atomic opcodes correctly. The function only handles non-masked opcodes, and when a masked atomic completion is encountered, it falls through to the default case and returns a NULL pointer. The rds_ib_send_cqe_handler() function then dereferences this NULL pointer, causing a NULL pointer dereference error. The issue can be resolved by properly handling masked atomic opcodes in the rds_ib_send_unmap_op() function.

Defensive priority

High

Recommended defensive actions

  • Apply the official patch or update to a fixed version of the Linux kernel
  • Restrict access to RDS/IB connections to only privileged users
  • Monitor system logs for suspicious activity related to RDS/IB
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability was resolved by handling masked atomic opcodes in the same case as non-masked ones. The existing container_of()/rds_ib_send_unmap_atomic() body is correct for them. The fix involves modifying the rds_ib_send_unmap_op() function to properly handle masked atomic completions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-52939 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-52939

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-52939 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52939

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0f22412a2f4fbbe0251c132abee045d15a90e5b6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0f7baa82a24813cdad0b06a6f8f07e4824af5ed5

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/34080db3e70ddf94c38512ad2331e3c3afca6cc1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4dd262f875e87653df50b138de1390ab0628e6b7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4fd34669558085bcb589aa2078a13b0ca79e360d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6e4615164d185a26badb2f376a2449f4d174a5f0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a0148342badd8c9b2e46551766a27cb76c82e715

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.