CVE-2026-98355: RDMA/rtrs: guard against null kobj name
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rtrs: guard against null kobj name
In the client, if initpath() errors, the callee tries to clean up with rtrscltcloseconns(). However, this can lead to calling the event tracing code with cltpath->kobj->name being NULL and thus causing a null pointer dereference when trying to copy from it.
This just adds a guard to check that the name is not NULL before copying from it. The server appears to have a similar pattern.
Affected Software
Event History
Frequently Asked Questions
What condition triggers the crash?
The client-side cleanup path can trigger it when init_path() fails and rtrs_clt_close_conns() subsequently invokes event tracing while clt_path->kobj->name is NULL. Copying from that NULL name causes a null pointer dereference.
Is the issue limited to RTRS clients?
The described trigger is in the client cleanup path. The available information also notes that the server appears to have a similar pattern, but does not confirm the same vulnerability or trigger on the server.
What is the practical mitigation if an update cannot be applied immediately?
Avoid or investigate init_path() failures in RTRS client setup, since the vulnerable cleanup sequence follows such a failure. The provided information does not identify a configuration-based workaround or a way to disable the affected tracing path.