7.5

CVE-2026-89528

svcrdma: Reject Read lists that exceed the page budget

In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Reject Read lists that exceed the page budget

Individual Read segment lengths are validated at decode time, but
nothing prevents a requester from sending multiple segments whose
cumulative length exceeds the rq_pages array budget. When one
segment fills the page array exactly, the runtime guard in
svc_rdma_build_read_segment() is bypassed because len reaches zero.
A subsequent segment then accesses the NULL sentinel slot at
rq_pages[rq_maxpages], resulting in a NULL pointer dereference during
DMA mapping.

Accumulate pages across all Read segments and reject the message at
decode time when the total would overflow the page budget.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 026d958b38c628a1b4ced534808945365e2747a5
Version < 1a3af2262cb384112ef38632de4690682be528b4
Status affected
Version 026d958b38c628a1b4ced534808945365e2747a5
Version < 465f511f59a0fa7a80d5d1073c4b24f28ea38f58
Status affected
Version 026d958b38c628a1b4ced534808945365e2747a5
Version < 0ca487abb3bdf581851664b5db21f364caf57682
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.13
Status affected
Version 0
Version < 4.13
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.481
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1a3af2262cb384112ef38632de4690682be528b4
https://git.kernel.org/stable/c/465f511f59a0fa7a80d5d1073c4b24f28ea38f58
https://git.kernel.org/stable/c/0ca487abb3bdf581851664b5db21f364caf57682