Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89533

svcrdma: Fix offset arithmetic in read_chunk_range
Back to all
CVE

CVE-2026-89533

svcrdma: Fix offset arithmetic in read_chunk_range

In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Fix offset arithmetic in readchunkrange

svcrdmareadchunkrange() walks a Read chunk's segment list to

build a sub-range starting at byte offset and spanning length bytes

for a Position-Zero or Call chunk. Two arithmetic defects in the

per-segment loop produce wrong DMA lengths and a u32 underflow:

    pclforeach_segment(segment, chunk) {

            if (offset > segment->rs_length) {

                    offset -= segment->rs_length;

                    continue;

            }

            dummy.rshandle = segment->rshandle;

            dummy.rslength = mint(u32, length,

                                    segment->rs_length) - offset;

            dummy.rsoffset = segment->rsoffset + offset;

First, the skip predicate uses '>' instead of '>='. When offset

equals the segment's full rs_length, the segment is fully consumed

and should be skipped, but the loop falls through into the body.

The resulting dummy.rslength is mint(u32, length, rs_length) -

rslength, which underflows to a near-UINTMAX u32 when length is

smaller than rs_length, or is zero otherwise.

Second, the length formula subtracts offset from the min_t() result

rather than from segment->rs_length before the cap. For offset > 0

the segment's residual is rslength - offset, not rslength, so the

cap must be applied to the residual. With the current bracketing,

whenever length is smaller than rs_length - offset the per-segment

length becomes length - offset instead of length, silently dropping

offset bytes from the rebuilt chunk. Combined with the boundary

case above it also enables the u32 underflow path, which propagates

a huge nrbvec into svcrdmabuildread_segment() and a multi-MiB

kmallocarraynode() in svcrdmagetrwctxt().

Additionally, svcrdmareadcallchunk() can invoke this function

with length == 0 when the last Read chunk ends exactly at the end

of the Call chunk. With the corrected >= predicate, every segment

is skipped and the function returns the initial -EINVAL, rejecting

a valid request. Return success immediately when length is zero.

Also break out of the loop once length is fully consumed to avoid

passing zero-length segments to svcrdmabuildreadsegment().

Fix by using '>=' so a fully-consumed segment is skipped, by

moving '- offset' inside min_t() so the cap is applied to the

segment's residual length, by returning success for zero-length

requests, and by stopping iteration when the requested range has

been consumed.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/10873311f91db9454e2fadbf9866bc819e0646d9, https://git.kernel.org/stable/c/4493c96bbd0068fadf69cbae8d13426202e34cdc, https://git.kernel.org/stable/c/4a44c140cc2f3643a39e258bb0c0ab9d0f494f5e, https://git.kernel.org/stable/c/6ee4dc7476b3abc92ec1d444533a559f33f59561, https://git.kernel.org/stable/c/a46b35f213c2426f5d6a0458a8f7e873fc59cdfd, https://git.kernel.org/stable/c/addbf02dfe3b25e7e38e03bbd4e2a6ed86a14be7, https://git.kernel.org/stable/c/cba8543c18cf42fd80fd63effb6df6ff4f7e73ce, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89533.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89533, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00502%
EPSS Percentile
0.41056%
Introduced Version
d7cc73972661be4a02a1b09f1d9b3283c6c05154,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
4a44c140cc2f3643a39e258bb0c0ab9d0f494f5e,5.15.221,6.1.188,6.6.157,6.12.109,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading