CVE-2026-89533
Received Received - Intake

Buffer Overflow Fix in Linux Kernel svcrdma Module

Vulnerability report for CVE-2026-89533, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix offset arithmetic in read_chunk_range svc_rdma_read_chunk_range() walks a Read chunk's segment list to build a sub-range starting at byte offset and spanning length bytes for a Position-Zero or Call chunk. Two arithmetic defects in the per-segment loop produce wrong DMA lengths and a u32 underflow: pcl_for_each_segment(segment, chunk) { if (offset > segment->rs_length) { offset -= segment->rs_length; continue; } dummy.rs_handle = segment->rs_handle; dummy.rs_length = min_t(u32, length, segment->rs_length) - offset; dummy.rs_offset = segment->rs_offset + offset; First, the skip predicate uses '>' instead of '>='. When offset equals the segment's full rs_length, the segment is fully consumed and should be skipped, but the loop falls through into the body. The resulting dummy.rs_length is min_t(u32, length, rs_length) - rs_length, which underflows to a near-UINT_MAX u32 when length is smaller than rs_length, or is zero otherwise. Second, the length formula subtracts offset from the min_t() result rather than from segment->rs_length before the cap. For offset > 0 the segment's residual is rs_length - offset, not rs_length, so the cap must be applied to the residual. With the current bracketing, whenever length is smaller than rs_length - offset the per-segment length becomes length - offset instead of length, silently dropping offset bytes from the rebuilt chunk. Combined with the boundary case above it also enables the u32 underflow path, which propagates a huge nr_bvec into svc_rdma_build_read_segment() and a multi-MiB kmalloc_array_node() in svc_rdma_get_rw_ctxt(). Additionally, svc_rdma_read_call_chunk() can invoke this function with length == 0 when the last Read chunk ends exactly at the end of the Call chunk. With the corrected >= predicate, every segment is skipped and the function returns the initial -EINVAL, rejecting a valid request. Return success immediately when length is zero. Also break out of the loop once length is fully consumed to avoid passing zero-length segments to svc_rdma_build_read_segment(). Fix by using '>=' so a fully-consumed segment is skipped, by moving '- offset' inside min_t() so the cap is applied to the segment's residual length, by returning success for zero-length requests, and by stopping iteration when the requested range has been consumed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in the Linux kernel's svcrdma module. It involves incorrect arithmetic in the svc_rdma_read_chunk_range() function, which processes Read chunks for remote direct memory access (RDMA). The issues include wrong offset comparisons, u32 underflow, and incorrect length calculations that can lead to memory allocation errors and crashes.

Detection Guidance

This vulnerability is specific to the Linux kernel's svcrdma module and involves incorrect arithmetic in read chunk handling. Detection requires checking the kernel version and svcrdma module behavior. Use commands like 'uname -a' to check kernel version and 'lsmod | grep svcrdma' to verify if the module is loaded. Monitor kernel logs for errors related to svcrdma or NFS/RDMA operations.

Impact Analysis

An attacker could exploit this to cause a denial of service (DoS) by triggering large memory allocations or kernel crashes. Systems using NFS over RDMA may be affected, leading to service disruptions or instability.

Compliance Impact

This vulnerability is a low-level kernel memory handling issue in the Linux svcrdma subsystem. It does not directly impact compliance with GDPR, HIPAA, or similar standards as it is not a data breach or privacy violation. The issue involves incorrect DMA length calculations and potential memory allocation problems, which could lead to system instability or crashes but does not inherently cause unauthorized data access or exposure.

Mitigation Strategies

Apply the latest kernel patches from your distribution to fix the svcrdma arithmetic issues. If immediate patching is not possible, disable the svcrdma module using 'modprobe -r svcrdma' or block NFS over RDMA traffic at the network level. Ensure kernel logs are monitored for signs of exploitation or misconfiguration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89533. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart