CVE-2026-89529
In the Linux kernel, the following vulnerability has been resolved:
svcrdma: Reject oversized Read segments at decode time
The RPC/RDMA Read list decoder stores wire-supplied segment lengths without validation. xdr_count_read_segments() checks 4-byte alignment for non-zero position values but does not cap the segment length.
An oversized rs_length reaches svc_rdma_build_read_segment(), which derives nr_bvec from it and can drive a large dynamic bvec allocation before verifying that enough rq_pages remain. If the post-allocation page-overrun guard fires, the freshly acquired rw context is not returned, leaking the resource.
Leer descripción completaMostrar menos
Reject any segment whose length exceeds the receive context's page budget during Read list decoding, consistent with how xdr_check_write_chunk() bounds Write segment counts against rc_maxpages. Also return the rw context on the existing post-allocation overrun path in svc_rdma_build_read_segment(), keeping that defensive guard balanced.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89529",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5ee62b4a91137557ee4b09d1604f1dfd0b4344a8",
"lessThan": "5120fe54e0e2f5b62797a432115cc61d61117a5b",
"versionType": "git"
},
{
"status": "affected",
"version": "5ee62b4a91137557ee4b09d1604f1dfd0b4344a8",
"lessThan": "af6f0e06bed818ee7fc8b869915964410020a1c5",
"versionType": "git"
}
],
"programFiles": [
"net/sunrpc/xprtrdma/svc_rdma_recvfrom.c",
"net/sunrpc/xprtrdma/svc_rdma_rw.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "7.0"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "7.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/sunrpc/xprtrdma/svc_rdma_recvfrom.c",
"net/sunrpc/xprtrdma/svc_rdma_rw.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:19:35.740",
"references": [
{
"url": "https://git.kernel.org/stable/c/5120fe54e0e2f5b62797a432115cc61d61117a5b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/af6f0e06bed818ee7fc8b869915964410020a1c5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Reject oversized Read segments at decode time\n\nThe RPC/RDMA Read list decoder stores wire-supplied segment\nlengths without validation. xdr_count_read_segments() checks\n4-byte alignment for non-zero position values but does not\ncap the segment length.\n\nAn oversized rs_length reaches svc_rdma_build_read_segment(),\nwhich derives nr_bvec from it and can drive a large dynamic\nbvec allocation before verifying that enough rq_pages remain.\nIf the post-allocation page-overrun guard fires, the freshly\nacquired rw context is not returned, leaking the resource.\n\nReject any segment whose length exceeds the receive context's\npage budget during Read list decoding, consistent with how\nxdr_check_write_chunk() bounds Write segment counts against\nrc_maxpages. Also return the rw context on the existing\npost-allocation overrun path in svc_rdma_build_read_segment(),\nkeeping that defensive guard balanced."
}
],
"lastModified": "2026-09-11T20:19:35.740",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}