PatchSiren cyber security CVE debrief
CVE-2026-52939 Linux CVE debrief
A vulnerability in the Linux kernel's RDS/IB (Remote Direct Memory Access over InfiniBand) implementation could allow an unprivileged user to trigger a NULL pointer dereference. The issue arises from the handling of masked atomic completions in the rds_ib_send_cqe_handler() function. When a masked atomic opcode is used, the function does not properly handle it, leading to a NULL pointer dereference. This vulnerability can be triggered by sending an atomic cmsg over an active RDS/IB connection using the AF_RDS socket.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-24
- Original CVE updated
- 2026-07-08
- Advisory published
- 2026-06-24
- Advisory updated
- 2026-07-08
Who should care
System administrators and users of Linux-based systems, particularly those using RDS/IB, should be aware of this vulnerability. An unprivileged user could potentially exploit this vulnerability to cause a denial-of-service (DoS) or possibly execute arbitrary code with elevated privileges.
Technical summary
The vulnerability is caused by the rds_ib_send_unmap_op() function not handling masked atomic opcodes correctly. The function only handles non-masked opcodes, and when a masked atomic completion is encountered, it falls through to the default case and returns a NULL pointer. The rds_ib_send_cqe_handler() function then dereferences this NULL pointer, causing a NULL pointer dereference error. The issue can be resolved by properly handling masked atomic opcodes in the rds_ib_send_unmap_op() function.
Defensive priority
High
Recommended defensive actions
- Apply the official patch or update to a fixed version of the Linux kernel
- Restrict access to RDS/IB connections to only privileged users
- Monitor system logs for suspicious activity related to RDS/IB
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability was resolved by handling masked atomic opcodes in the same case as non-masked ones. The existing container_of()/rds_ib_send_unmap_atomic() body is correct for them. The fix involves modifying the rds_ib_send_unmap_op() function to properly handle masked atomic completions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-52939 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-52939
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-52939 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52939
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0f22412a2f4fbbe0251c132abee045d15a90e5b6
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0f7baa82a24813cdad0b06a6f8f07e4824af5ed5
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/34080db3e70ddf94c38512ad2331e3c3afca6cc1
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4dd262f875e87653df50b138de1390ab0628e6b7
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4fd34669558085bcb589aa2078a13b0ca79e360d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6e4615164d185a26badb2f376a2449f4d174a5f0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a0148342badd8c9b2e46551766a27cb76c82e715
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.