Unity Linux 20.1050e Security Update: kernel (UTSA-2026-099910)

high Nessus Plugin ID 336399

Synopsis

The Unity Linux host is missing one or more security updates.

Description

The Unity Linux 20 host has a package installed that is affected by a vulnerability as referenced in the UTSA-2026-099910 advisory.

In the Linux kernel, the following vulnerability has been resolved:

net/rds: No shortcut out of RDS_CONN_ERROR

RDS connections carry a state rds_conn_path::cp_state and transitions from one state to another and are conditional upon an expected state: rds_conn_path_transition.

There is one exception to this conditionality, which is RDS_CONN_ERROR that can be enforced by rds_conn_path_drop regardless of what state the condition is currently in.

But as soon as a connection enters state RDS_CONN_ERROR, the connection handling code expects it to go through the shutdown-path.

The RDS/TCP multipath changes added a shortcut out of RDS_CONN_ERROR straight back to RDS_CONN_CONNECTING via rds_tcp_accept_one_path (e.g. after rds_tcp_state_change).

A subsequent rds_tcp_reset_callbacks can then transition the state to RDS_CONN_RESETTING with a shutdown-worker queued.

That'll trip up rds_conn_init_shutdown, which was never adjusted to handle RDS_CONN_RESETTING and subsequently drops the connection with the dreaded DR_INV_CONN_STATE, which leaves RDS_SHUTDOWN_WORK_QUEUED on forever.

So we do two things here:

a) Don't shortcut RDS_CONN_ERROR, but take the longer path through the shutdown code.

b) Add RDS_CONN_RESETTING to the expected states in rds_conn_init_shutdown so that we won't error out and get stuck, if we ever hit weird state transitions like this again.

Tenable has extracted the preceding description block directly from the Unity Linux security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected kernel package.

See Also

https://nvd.nist.gov/vuln/detail/CVE-2026-43226

http://www.nessus.org/u?6af79f38

http://www.nessus.org/u?feb54e41

Plugin Details

Severity: High

ID: 336399

File Name: unity_linux_UTSA-2026-099910.nasl

Version: 1.1

Type: Local

Published: 8/17/2026

Updated: 8/17/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.75

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-43226

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/UOS-Server/release, Host/UOS-Server/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/13/2026

Vulnerability Publication Date: 3/12/2026

Reference Information

CVE: CVE-2026-43226