CVE-2026-89526
In the Linux kernel, the following vulnerability has been resolved:
svcrdma: Validate Read chunk positions before reconstruction
The RPC/RDMA Read chunk position field is supplied by the remote
client and stored verbatim in the parsed chunk list.
xdrcountread_segments() checks only 4-byte alignment; it never
compares the position against the received inline body length.
In the single-chunk path, svcrdmareadcompleteone() splits the
head and tail kvecs at ch_position. A position past the inline
body underflows the tail length, exposing adjacent slab memory to
the upper XDR decoder.
In the multi-chunk path, svcrdmareadmultiplechunks() computes
gap lengths between chunks as unsigned subtractions from
ch_position. Overlapping Read chunks cause these subtractions to
underflow. A final position past the inline body likewise
underflows the trailing gap length. svcrdmacopyinlinerange()
then copies past the receive buffer into request pages that are
returned to the client through the Reply channel.
Bound inline-range copies in svcrdmacopyinlinerange() against
the decoded inline RPC body saved in rcsavedarg. Reject a
single Read chunk positioned beyond that body, and reject
multi-chunk lists where accumulated read bytes exceed the next
chunk's position. Apply the same position and overlap checks in
the call-chunk interleaving path.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/3779b7b9e7d1c8ba4738f9d327de3b0288cefe9b, https://git.kernel.org/stable/c/577097455d084610fc31e91e6a61c5793b6f04ba, https://git.kernel.org/stable/c/5ab3f6d882fe07ae5e61d0bcfeea00b9409155c2, https://git.kernel.org/stable/c/f84ec84d8d4bc65f9ae23372570349687f66fa39, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89526.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89526, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git