CVE-2026-89529
Received Received - Intake

Buffer Overflow in Linux Kernel RPC/RDMA

Vulnerability report for CVE-2026-89529, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject oversized Read segments at decode time The RPC/RDMA Read list decoder stores wire-supplied segment lengths without validation. xdr_count_read_segments() checks 4-byte alignment for non-zero position values but does not cap the segment length. An oversized rs_length reaches svc_rdma_build_read_segment(), which derives nr_bvec from it and can drive a large dynamic bvec allocation before verifying that enough rq_pages remain. If the post-allocation page-overrun guard fires, the freshly acquired rw context is not returned, leaking the resource. Reject any segment whose length exceeds the receive context's page budget during Read list decoding, consistent with how xdr_check_write_chunk() bounds Write segment counts against rc_maxpages. Also return the rw context on the existing post-allocation overrun path in svc_rdma_build_read_segment(), keeping that defensive guard balanced.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves the RPC/RDMA Read list decoder not validating segment lengths properly. It allows an oversized segment length to trigger a large dynamic allocation before checking available pages, potentially causing a page overrun. The fix ensures segment lengths are capped against the receive context's page budget during decoding.

Detection Guidance

This vulnerability involves the Linux kernel's RPC/RDMA Read list decoder handling oversized segments. Detection requires checking kernel logs for svcrdma-related errors or crashes, particularly during RDMA operations. Monitor for messages indicating page overruns or failed allocations in svc_rdma_build_read_segment. Use commands like dmesg | grep svcrdma or journalctl -k | grep svcrdma to inspect kernel logs for suspicious activity.

Impact Analysis

An attacker could exploit this to cause resource exhaustion or memory corruption in systems using RPC/RDMA, leading to denial of service or potential privilege escalation. Systems relying on RPC/RDMA for remote file access or distributed computing may be affected.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it pertains to a low-level kernel memory management issue in the Linux kernel's RPC/RDMA subsystem. Compliance impacts would only occur if exploitation led to data breaches or unauthorized access, which is not described in the provided context.

Mitigation Strategies

Update the Linux kernel to the latest patched version to resolve the svcrdma Read segment validation issue. Monitor for unusual network traffic or resource leaks related to RPC/RDMA operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89529. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart