In the Linux kernel, the following vulnerability has been resolved: svcrdma: Validate Read chunk positions before reconstruction The RPC/RDMA Read… (CVE-2026-89526)
A vulnerability in the Linux kernel's svcrdma component related to RPC/RDMA Read chunk position validation has been resolved. The flaw involves improper validation of Read chunk positions supplied by remote clients, leading to potential memory underflow and out-of-bounds copying. This could expose adjacent memory to decoding processes or cause copying beyond buffer boundaries. The fix enforces bounds checking on inline-range copies and rejects invalid chunk positions and overlaps.
AI Analysis
Technical Summary
The Linux kernel svcrdma subsystem had a vulnerability where the RPC/RDMA Read chunk position field, provided by remote clients, was stored without sufficient validation. The function xdr_count_read_segments() only checked 4-byte alignment but did not verify that positions were within the inline body length. This allowed, in single-chunk scenarios, splitting of kvecs at positions past the inline body, causing tail length underflow and exposure of adjacent slab memory. In multi-chunk scenarios, overlapping chunks caused unsigned subtraction underflows, and positions beyond the inline body caused underflows in gap length calculations. This led to svc_rdma_copy_inline_range() copying beyond the receive buffer into request pages, which are then returned to clients. The vulnerability was mitigated by adding bounds checks against the decoded inline RPC body, rejecting single chunks beyond the body and multi-chunk lists with excessive accumulated read bytes, and applying similar checks in call-chunk interleaving.
Potential Impact
The vulnerability could allow a remote client to cause out-of-bounds memory reads or memory exposure by supplying crafted RPC/RDMA Read chunk positions. This could lead to exposure of adjacent kernel memory or copying beyond intended buffers, potentially compromising kernel memory integrity or causing denial of service. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to validate Read chunk positions before reconstruction. The fix bounds inline-range copies against the decoded inline RPC body and rejects invalid chunk positions and overlaps. Users should apply the official Linux kernel updates that include this patch. Since no vendor advisory or patch links are provided here, check the Linux kernel mailing lists or official repositories for the relevant patch and update accordingly.
In the Linux kernel, the following vulnerability has been resolved: svcrdma: Validate Read chunk positions before reconstruction The RPC/RDMA Read… (CVE-2026-89526)
Description
A vulnerability in the Linux kernel's svcrdma component related to RPC/RDMA Read chunk position validation has been resolved. The flaw involves improper validation of Read chunk positions supplied by remote clients, leading to potential memory underflow and out-of-bounds copying. This could expose adjacent memory to decoding processes or cause copying beyond buffer boundaries. The fix enforces bounds checking on inline-range copies and rejects invalid chunk positions and overlaps.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel svcrdma subsystem had a vulnerability where the RPC/RDMA Read chunk position field, provided by remote clients, was stored without sufficient validation. The function xdr_count_read_segments() only checked 4-byte alignment but did not verify that positions were within the inline body length. This allowed, in single-chunk scenarios, splitting of kvecs at positions past the inline body, causing tail length underflow and exposure of adjacent slab memory. In multi-chunk scenarios, overlapping chunks caused unsigned subtraction underflows, and positions beyond the inline body caused underflows in gap length calculations. This led to svc_rdma_copy_inline_range() copying beyond the receive buffer into request pages, which are then returned to clients. The vulnerability was mitigated by adding bounds checks against the decoded inline RPC body, rejecting single chunks beyond the body and multi-chunk lists with excessive accumulated read bytes, and applying similar checks in call-chunk interleaving.
Potential Impact
The vulnerability could allow a remote client to cause out-of-bounds memory reads or memory exposure by supplying crafted RPC/RDMA Read chunk positions. This could lead to exposure of adjacent kernel memory or copying beyond intended buffers, potentially compromising kernel memory integrity or causing denial of service. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to validate Read chunk positions before reconstruction. The fix bounds inline-range copies against the decoded inline RPC body and rejects invalid chunk positions and overlaps. Users should apply the official Linux kernel updates that include this patch. Since no vendor advisory or patch links are provided here, check the Linux kernel mailing lists or official repositories for the relevant patch and update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jj8v-vrfx-wp8w
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-89526"]
Threat ID: 6aa4a01455bf5e2cf5a866d2
Added to database: 09/12/2026, 00:43:00 UTC
Last enriched: 09/12/2026, 01:10:08 UTC
Last updated: 09/12/2026, 01:10:08 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.