Skip to main content

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Validate Read chunk positions before reconstruction The RPC/RDMA Read… (CVE-2026-89526)

0
High
Published: 09/11/2026 (09/11/2026, 21:31:30 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel's svcrdma component related to RPC/RDMA Read chunk position validation has been resolved. The flaw involves improper validation of Read chunk positions supplied by remote clients, leading to potential memory underflow and out-of-bounds copying. This could expose adjacent memory to decoding processes or cause copying beyond buffer boundaries. The fix enforces bounds checking on inline-range copies and rejects invalid chunk positions and overlaps.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/12/2026, 01:10:08 UTC

Technical Analysis

The Linux kernel svcrdma subsystem had a vulnerability where the RPC/RDMA Read chunk position field, provided by remote clients, was stored without sufficient validation. The function xdr_count_read_segments() only checked 4-byte alignment but did not verify that positions were within the inline body length. This allowed, in single-chunk scenarios, splitting of kvecs at positions past the inline body, causing tail length underflow and exposure of adjacent slab memory. In multi-chunk scenarios, overlapping chunks caused unsigned subtraction underflows, and positions beyond the inline body caused underflows in gap length calculations. This led to svc_rdma_copy_inline_range() copying beyond the receive buffer into request pages, which are then returned to clients. The vulnerability was mitigated by adding bounds checks against the decoded inline RPC body, rejecting single chunks beyond the body and multi-chunk lists with excessive accumulated read bytes, and applying similar checks in call-chunk interleaving.

Potential Impact

The vulnerability could allow a remote client to cause out-of-bounds memory reads or memory exposure by supplying crafted RPC/RDMA Read chunk positions. This could lead to exposure of adjacent kernel memory or copying beyond intended buffers, potentially compromising kernel memory integrity or causing denial of service. No known exploits in the wild have been reported.

Mitigation Recommendations

A fix has been implemented in the Linux kernel to validate Read chunk positions before reconstruction. The fix bounds inline-range copies against the decoded inline RPC body and rejects invalid chunk positions and overlaps. Users should apply the official Linux kernel updates that include this patch. Since no vendor advisory or patch links are provided here, check the Linux kernel mailing lists or official repositories for the relevant patch and update accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-jj8v-vrfx-wp8w
Osv Schema Version
1.4.0
Aliases
["CVE-2026-89526"]

Threat ID: 6aa4a01455bf5e2cf5a866d2

Added to database: 09/12/2026, 00:43:00 UTC

Last enriched: 09/12/2026, 01:10:08 UTC

Last updated: 09/12/2026, 01:10:08 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses