Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89526

svcrdma: Validate Read chunk positions before reconstruction
Back to all
CVE

CVE-2026-89526

svcrdma: Validate Read chunk positions before reconstruction

In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Validate Read chunk positions before reconstruction

The RPC/RDMA Read chunk position field is supplied by the remote

client and stored verbatim in the parsed chunk list.

xdrcountread_segments() checks only 4-byte alignment; it never

compares the position against the received inline body length.

In the single-chunk path, svcrdmareadcompleteone() splits the

head and tail kvecs at ch_position. A position past the inline

body underflows the tail length, exposing adjacent slab memory to

the upper XDR decoder.

In the multi-chunk path, svcrdmareadmultiplechunks() computes

gap lengths between chunks as unsigned subtractions from

ch_position. Overlapping Read chunks cause these subtractions to

underflow. A final position past the inline body likewise

underflows the trailing gap length. svcrdmacopyinlinerange()

then copies past the receive buffer into request pages that are

returned to the client through the Reply channel.

Bound inline-range copies in svcrdmacopyinlinerange() against

the decoded inline RPC body saved in rcsavedarg. Reject a

single Read chunk positioned beyond that body, and reject

multi-chunk lists where accumulated read bytes exceed the next

chunk's position. Apply the same position and overlap checks in

the call-chunk interleaving path.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/3779b7b9e7d1c8ba4738f9d327de3b0288cefe9b, https://git.kernel.org/stable/c/577097455d084610fc31e91e6a61c5793b6f04ba, https://git.kernel.org/stable/c/5ab3f6d882fe07ae5e61d0bcfeea00b9409155c2, https://git.kernel.org/stable/c/f84ec84d8d4bc65f9ae23372570349687f66fa39, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89526.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89526, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00635%
EPSS Percentile
0.4881%
Introduced Version
d96962e6d0e281bab6a48e83b42f5dce6eb28bf4,5.11.0,6.13.0,6.19.0,0
Fix Available
3779b7b9e7d1c8ba4738f9d327de3b0288cefe9b,6.12.109,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading