CVE-2026-89533
In the Linux kernel, the following vulnerability has been resolved:
svcrdma: Fix offset arithmetic in readchunkrange
svcrdmareadchunkrange() walks a Read chunk's segment list to
build a sub-range starting at byte offset and spanning length bytes
for a Position-Zero or Call chunk. Two arithmetic defects in the
per-segment loop produce wrong DMA lengths and a u32 underflow:
pclforeach_segment(segment, chunk) {
if (offset > segment->rs_length) {
offset -= segment->rs_length;
continue;
}
dummy.rshandle = segment->rshandle;
dummy.rslength = mint(u32, length,
segment->rs_length) - offset;
dummy.rsoffset = segment->rsoffset + offset;
First, the skip predicate uses '>' instead of '>='. When offset
equals the segment's full rs_length, the segment is fully consumed
and should be skipped, but the loop falls through into the body.
The resulting dummy.rslength is mint(u32, length, rs_length) -
rslength, which underflows to a near-UINTMAX u32 when length is
smaller than rs_length, or is zero otherwise.
Second, the length formula subtracts offset from the min_t() result
rather than from segment->rs_length before the cap. For offset > 0
the segment's residual is rslength - offset, not rslength, so the
cap must be applied to the residual. With the current bracketing,
whenever length is smaller than rs_length - offset the per-segment
length becomes length - offset instead of length, silently dropping
offset bytes from the rebuilt chunk. Combined with the boundary
case above it also enables the u32 underflow path, which propagates
a huge nrbvec into svcrdmabuildread_segment() and a multi-MiB
kmallocarraynode() in svcrdmagetrwctxt().
Additionally, svcrdmareadcallchunk() can invoke this function
with length == 0 when the last Read chunk ends exactly at the end
of the Call chunk. With the corrected >= predicate, every segment
is skipped and the function returns the initial -EINVAL, rejecting
a valid request. Return success immediately when length is zero.
Also break out of the loop once length is fully consumed to avoid
passing zero-length segments to svcrdmabuildreadsegment().
Fix by using '>=' so a fully-consumed segment is skipped, by
moving '- offset' inside min_t() so the cap is applied to the
segment's residual length, by returning success for zero-length
requests, and by stopping iteration when the requested range has
been consumed.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/10873311f91db9454e2fadbf9866bc819e0646d9, https://git.kernel.org/stable/c/4493c96bbd0068fadf69cbae8d13426202e34cdc, https://git.kernel.org/stable/c/4a44c140cc2f3643a39e258bb0c0ab9d0f494f5e, https://git.kernel.org/stable/c/6ee4dc7476b3abc92ec1d444533a559f33f59561, https://git.kernel.org/stable/c/a46b35f213c2426f5d6a0458a8f7e873fc59cdfd, https://git.kernel.org/stable/c/addbf02dfe3b25e7e38e03bbd4e2a6ed86a14be7, https://git.kernel.org/stable/c/cba8543c18cf42fd80fd63effb6df6ff4f7e73ce, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89533.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89533, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git