Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89532

svcrdma: Fix pcl_for_each_segment for empty chunks
Back to all
CVE

CVE-2026-89532

svcrdma: Fix pcl_for_each_segment for empty chunks

In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Fix pclforeach_segment for empty chunks

When a parsed chunk list contains a chunk whose ch_segcount is zero,

pclforeach_segment computes its inclusive upper bound as

&chunk->chsegments[chsegcount - 1]. ch_segcount is u32, so the

subtraction wraps to 0xFFFFFFFF and the bound lands far past the

ch_segments flex array. The loop body then walks unrelated memory at

sizeof(struct svcrdmasegment) stride until it faults.

A zero-segcount chunk is reachable from the wire:

xdrcheckwrite_chunk() only rejects segcount values greater than

rcmaxpages, and pclalloc_write() links a freshly allocated chunk

onto rcwritepcl/rcreplypcl before its segment-fill loop runs,

so a Write or Reply chunk advertising zero segments leaves

ch_segcount == 0 on the list. When the transport has negotiated

Send-With-Invalidate, svcrdmagetinvrkey() iterates all four

PCLs with pclforeachsegment and dereferences segment->rshandle

on each iteration, turning the underflow into an out-of-bounds read

and a general protection fault.

    xdrcheckwritelist / xdrcheckreplychunk

      pclallocwrite()

        chunk = pclallocchunk(...)  / ch_segcount = 0 /

        listaddtail(&chunk->chlist, &pcl->clchunks)

        / fill loop iterates zero times for wire segcount 0 /

    svcrdmagetinvrkey()

      pclforeachchunk(rcwrite_pcl)

        pclforeach_segment(segment, chunk)

          pos <= &ch_segments[0u - 1u]  / 0xFFFFFFFF /

          segment->rs_handle            / OOB read -> GPF /

Fix by switching the macro to a half-open upper bound that uses

chsegcount directly. For chsegcount == 0 the loop start equals the

loop end and the body is skipped; for ch_segcount > 0 the iteration

range is unchanged. All six existing call sites in

net/sunrpc/xprtrdma/svcrdmarecvfrom.c and

net/sunrpc/xprtrdma/svcrdmarw.c remain correct under the new bound,

so no caller changes are needed.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.1
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/06d0390c37fa6714624af771bd72bbf1a7ed9bb1, https://git.kernel.org/stable/c/1e2e3481e39103a386b86be1c33eaef97cbdf16e, https://git.kernel.org/stable/c/3a78b841879c2a3243f74edc514236fb2907167f, https://git.kernel.org/stable/c/6d33a7e6bf6c6b293a266a617201285a1ad32c56, https://git.kernel.org/stable/c/9c5a03c3dc505c0295339b0a1b9e4fe36447e482, https://git.kernel.org/stable/c/a1c954ca4977a4e6ec73ef92fe48073ec54f9fc8, https://git.kernel.org/stable/c/b7713a784c59515d0aba558c8f5df6a0164dd3a9, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89532.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89532, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.1

CVSS Score
0
10

Basic Information

Base CVSS
9.1
EPSS Probability
0.00502%
EPSS Percentile
0.41056%
Introduced Version
78147ca8b4a9b6cf0e597ddd6bf17959e08376c2,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
b7713a784c59515d0aba558c8f5df6a0164dd3a9,5.15.221,6.1.188,6.6.157,6.12.109,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading