CVE-2026-89532
In the Linux kernel, the following vulnerability has been resolved:
svcrdma: Fix pclforeach_segment for empty chunks
When a parsed chunk list contains a chunk whose ch_segcount is zero,
pclforeach_segment computes its inclusive upper bound as
&chunk->chsegments[chsegcount - 1]. ch_segcount is u32, so the
subtraction wraps to 0xFFFFFFFF and the bound lands far past the
ch_segments flex array. The loop body then walks unrelated memory at
sizeof(struct svcrdmasegment) stride until it faults.
A zero-segcount chunk is reachable from the wire:
xdrcheckwrite_chunk() only rejects segcount values greater than
rcmaxpages, and pclalloc_write() links a freshly allocated chunk
onto rcwritepcl/rcreplypcl before its segment-fill loop runs,
so a Write or Reply chunk advertising zero segments leaves
ch_segcount == 0 on the list. When the transport has negotiated
Send-With-Invalidate, svcrdmagetinvrkey() iterates all four
PCLs with pclforeachsegment and dereferences segment->rshandle
on each iteration, turning the underflow into an out-of-bounds read
and a general protection fault.
xdrcheckwritelist / xdrcheckreplychunk
pclallocwrite()
chunk = pclallocchunk(...) / ch_segcount = 0 /
listaddtail(&chunk->chlist, &pcl->clchunks)
/ fill loop iterates zero times for wire segcount 0 /
svcrdmagetinvrkey()
pclforeachchunk(rcwrite_pcl)
pclforeach_segment(segment, chunk)
pos <= &ch_segments[0u - 1u] / 0xFFFFFFFF /
segment->rs_handle / OOB read -> GPF /
Fix by switching the macro to a half-open upper bound that uses
chsegcount directly. For chsegcount == 0 the loop start equals the
loop end and the body is skipped; for ch_segcount > 0 the iteration
range is unchanged. All six existing call sites in
net/sunrpc/xprtrdma/svcrdmarecvfrom.c and
net/sunrpc/xprtrdma/svcrdmarw.c remain correct under the new bound,
so no caller changes are needed.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/06d0390c37fa6714624af771bd72bbf1a7ed9bb1, https://git.kernel.org/stable/c/1e2e3481e39103a386b86be1c33eaef97cbdf16e, https://git.kernel.org/stable/c/3a78b841879c2a3243f74edc514236fb2907167f, https://git.kernel.org/stable/c/6d33a7e6bf6c6b293a266a617201285a1ad32c56, https://git.kernel.org/stable/c/9c5a03c3dc505c0295339b0a1b9e4fe36447e482, https://git.kernel.org/stable/c/a1c954ca4977a4e6ec73ef92fe48073ec54f9fc8, https://git.kernel.org/stable/c/b7713a784c59515d0aba558c8f5df6a0164dd3a9, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89532.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89532, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git