$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
● CISA KEV 미등재

CVE-2026-98070

In the Linux kernel, the following vulnerability has been resolved: net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks() rds_tcp_reset_callbacks() quiesces the transmit path by setting the path s…

높음8.1악용 확률 0.42%공개 2026-09-25
8.129

📌 이 취약점에 대해 확인된 사실

전부 발행처가 발표한 값입니다. 우리가 계산하거나 판단한 숫자는 하나도 없습니다.

악용 여부

CISA KEV 목록에 없습니다. 악용이 없다는 증명이 아니라, 미국 정부가 악용을 확인해 등재한 적이 없다는 뜻입니다.

심각도 (발행처 발표값)

높음8.1

CVSS 버전3.1
평가 기관CNA (취약점 발행기관)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

악용 확률 (EPSS)

0.4%

30일 내 악용 확률0.42%
전체 CVE 중 백분위34.1%
기준일2026-09-29

🇰🇷 한국어 공식 권고

KISA 보호나라 권고문 본문에서 이 CVE 번호가 발견된 문서입니다.

전체 권고 ›
이 CVE 를 다룬 KISA 보호나라 권고를 아직 찾지 못했습니다. 권고가 없다는 확증은 아닙니다 — 우리는 RSS 로 공개된 최근 공지만 수집합니다.

📄 원문 그대로

아래 문장은 전부 발행처가 쓴 것입니다. 번역하지 않습니다 — 보안 문서의 오역은 조치를 바꿉니다.

취약점 설명 (NVD)

In the Linux kernel, the following vulnerability has been resolved: net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks() rds_tcp_reset_callbacks() quiesces the transmit path by setting the path state to RDS_CONN_RESETTING and then waiting for RDS_IN_XMIT to be sampled clear before swapping the underlying socket and calling rds_send_path_reset(). Sampling the bit clear is not the same as owning it: rds_send_xmit() can re-acquire RDS_IN_XMIT right after the wait_event() returns. Its state recheck after taking the lock is a store-buffering pattern (the resetter writes the state and reads the bit, the sender writes the bit and reads the state) and acquire_in_xmit() is only an acquire operation, so on weakly ordered architectures both sides can miss each other's write and the transmit path then runs concurrently with rds_send_path_reset() rewriting cp_xmit_* state - which is exactly what the comment above rds_send_path_reset() tells its callers to prevent. Take the lock instead, hold it across the socket swap and rds_send_path_reset(), and release it with a wake-up at the end. The lock-ordering constraint documented above the wait still holds: the lock is acquired before lock_sock(), so a sender inside tcp_sendmsg() can never be waited on while we hold the socket lock. Two details of the old code go away with the same change: - t_sock is now read only after the lock is acquired. The old code cached it before waiting; the teardown in rds_conn_shutdown() releases that socket and clears t_sock, so a pointer cached before the wait can be stale by the time the accept path resumes. Reading it under RDS_IN_XMIT is what makes the exclusion complete once the teardown owns the same lock, which the next patch arranges; until then the teardown still only samples the bit, and the two paths remain as exposed to each other as they are today. - The old !osock early path called rds_send_path_reset() with no serialization at all. It now runs under the lock like the normal path. The conditional RDS_CONN_RESETTING transition of the previous patch happens before the socket check either way: a path found without a socket is either still connecting (its reconnect worker blocked on t_conn_path_lock) and legitimately goes RESETTING -> UP on the new socket, or it has been torn down meanwhile and is dropped. The in-function comment describing the old wait-based quiesce is rewritten to describe the lock-based one, and the stale block comment above the function (which still described a return value and an incomplete list of t_sock writers) is refreshed to name all four writers - the connect, accept, teardown and swap paths - and what serializes each of them.

참조 문서 4건 · NVD 분석 상태 Received · 수집 2026-09-27

참고

이 취약점은 CISA KEV 에 등재되지 않아 CISA 원문이 없습니다. 영향 범위와 패치 버전은 제품 버전·구성에 따라 다르므로 반드시 공급사 공식 권고와 NVD 원문의 참조 링크를 확인하세요.

악용 확률 변화

우리가 매일 저장한 EPSS 스냅샷입니다. 원본은 전날 값만 주므로, 이 표는 수집을 시작한 이후만 보여줍니다.

기준일확률백분위
2026-09-290.42%34.1%
2026-09-270.42%34.1%
2026-09-260.42%34.0%
이 페이지는 조치 지시가 아닙니다. 영향 범위와 패치 버전은 제품·구성에 따라 다르므로, 반드시 공급사 공식 권고와 NVD 원문의 참조 링크를 확인하세요.