« Volver al listado

CVE-2026-89528

Estado: RecibidaAlta (7.5)—

In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Reject Read lists that exceed the page budget

Individual Read segment lengths are validated at decode time, but nothing prevents a requester from sending multiple segments whose cumulative length exceeds the rq_pages array budget. When one segment fills the page array exactly, the runtime guard in svc_rdma_build_read_segment() is bypassed because len reaches zero. A subsequent segment then accesses the NULL sentinel slot at rq_pages[rq_maxpages], resulting in a NULL pointer dereference during DMA mapping.

Accumulate pages across all Read segments and reject the message at decode time when the total would overflow the page budget.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Kernel svcrdma permite denegación de servicio mediante lista Read malformada en red sin autenticación (AV:N, PR:N). NULL pointer dereference causa crash.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89528",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "026d958b38c628a1b4ced534808945365e2747a5",
              "lessThan": "1a3af2262cb384112ef38632de4690682be528b4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "026d958b38c628a1b4ced534808945365e2747a5",
              "lessThan": "465f511f59a0fa7a80d5d1073c4b24f28ea38f58",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "026d958b38c628a1b4ced534808945365e2747a5",
              "lessThan": "0ca487abb3bdf581851664b5db21f364caf57682",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/sunrpc/xprtrdma/svc_rdma_recvfrom.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/sunrpc/xprtrdma/svc_rdma_recvfrom.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:35.613",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0ca487abb3bdf581851664b5db21f364caf57682",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1a3af2262cb384112ef38632de4690682be528b4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/465f511f59a0fa7a80d5d1073c4b24f28ea38f58",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Reject Read lists that exceed the page budget\n\nIndividual Read segment lengths are validated at decode time, but\nnothing prevents a requester from sending multiple segments whose\ncumulative length exceeds the rq_pages array budget. When one\nsegment fills the page array exactly, the runtime guard in\nsvc_rdma_build_read_segment() is bypassed because len reaches zero.\nA subsequent segment then accesses the NULL sentinel slot at\nrq_pages[rq_maxpages], resulting in a NULL pointer dereference during\nDMA mapping.\n\nAccumulate pages across all Read segments and reject the message at\ndecode time when the total would overflow the page budget."
    }
  ],
  "lastModified": "2026-09-13T07:17:15.120",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}