9.8
CVE-2026-89530
- EPSS 0.46%
- Veröffentlicht 11.09.2026 19:44:10
- Zuletzt bearbeitet 13.09.2026 07:17:15
- Erkennungen
svcrdma: Reject inline replies that overflow the pull-up buffer
In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject inline replies that overflow the pull-up buffer An RPC-over-RDMA client can request a reply, such as an NFS READ payload, without providing a Write list or a Reply chunk to carry it. When such a reply needs more scatter/gather entries than the device's Send Queue supports, svc_rdma_pull_up_needed() selects pull-up and svc_rdma_pull_up_reply_msg() linearizes the whole reply into sctxt->sc_xprt_buf. That buffer is only sc_max_req_size bytes, while the reply on this path is bounded only by the client's request, so svc_rdma_xb_linearize() copies past the end of the buffer and corrupts adjacent slab memory. The oversized length is then stored in sc_sges[0].length and posted, so the device also reads beyond the mapped region. The SGE-exhaustion branch is the only pull-up path that can exceed the buffer: the threshold branch pulls up only replies smaller than RPCRDMA_PULLUP_THRESH, and replies that fit the device's SGE budget are sent directly without linearization. Make svc_rdma_pull_up_needed() report -E2BIG when the reply it would pull up cannot fit sc_max_req_size, and fail the request with ERR_CHUNK as RFC 8166 Section 4.5.3 directs rather than dropping the connection. The helper no longer answers a simple yes/no question: it now reports pull-up, no pull-up, or -E2BIG for a reply too large to linearize. Rename svc_rdma_pull_up_needed() to svc_rdma_check_pull_up() so its name no longer implies a boolean predicate.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
e248aa7be86e8179f20ac0931774ecd746f3f5bf
Version <
fcd91b9957462d398792201c239dffaeff1cc8b2
Status
affected
Version
e248aa7be86e8179f20ac0931774ecd746f3f5bf
Version <
1949dd1576f7a8aa161b1330c6125df9d53046d5
Status
affected
Version
e248aa7be86e8179f20ac0931774ecd746f3f5bf
Version <
8ec60eb51fae37cd3d334ff26e4a7d6fb21ff7cf
Status
affected
Version
e248aa7be86e8179f20ac0931774ecd746f3f5bf
Version <
0fbe20dfe74b783d255bf389a6ea77aa25dc7860
Status
affected
Version
9b65b18f817d9ada2bf67351f24bdcce6789a0bb
Status
affected
Version
d564356e1919d1178568c19af410cfc1a9076663
Status
affected
Version
4.19.22
Version <
4.20
Status
affected
Version
4.20.9
Version <
4.21
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.0
Status
affected
Version
0
Version <
5.0
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.46% | 0.388 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/fcd91b9957462d398792201c239dffaeff1cc8b2
https://git.kernel.org/stable/c/1949dd1576f7a8aa161b1330c6125df9d53046d5
https://git.kernel.org/stable/c/8ec60eb51fae37cd3d334ff26e4a7d6fb21ff7cf
https://git.kernel.org/stable/c/0fbe20dfe74b783d255bf389a6ea77aa25dc7860