9.1

CVE-2026-89532

svcrdma: Fix pcl_for_each_segment for empty chunks

In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Fix pcl_for_each_segment for empty chunks

When a parsed chunk list contains a chunk whose ch_segcount is zero,
pcl_for_each_segment computes its inclusive upper bound as
&chunk->ch_segments[ch_segcount - 1]. ch_segcount is u32, so the
subtraction wraps to 0xFFFFFFFF and the bound lands far past the
ch_segments flex array. The loop body then walks unrelated memory at
sizeof(struct svc_rdma_segment) stride until it faults.

A zero-segcount chunk is reachable from the wire:
xdr_check_write_chunk() only rejects segcount values greater than
rc_maxpages, and pcl_alloc_write() links a freshly allocated chunk
onto rc_write_pcl/rc_reply_pcl before its segment-fill loop runs,
so a Write or Reply chunk advertising zero segments leaves
ch_segcount == 0 on the list. When the transport has negotiated
Send-With-Invalidate, svc_rdma_get_inv_rkey() iterates all four
PCLs with pcl_for_each_segment and dereferences segment->rs_handle
on each iteration, turning the underflow into an out-of-bounds read
and a general protection fault.

    xdr_check_write_list / xdr_check_reply_chunk
      pcl_alloc_write()
        chunk = pcl_alloc_chunk(...)  /* ch_segcount = 0 */
        list_add_tail(&chunk->ch_list, &pcl->cl_chunks)
        /* fill loop iterates zero times for wire segcount 0 */

    svc_rdma_get_inv_rkey()
      pcl_for_each_chunk(rc_write_pcl)
        pcl_for_each_segment(segment, chunk)
          pos <= &ch_segments[0u - 1u]  /* 0xFFFFFFFF */
          segment->rs_handle            /* OOB read -> GPF */

Fix by switching the macro to a half-open upper bound that uses
ch_segcount directly. For ch_segcount == 0 the loop start equals the
loop end and the body is skipped; for ch_segcount > 0 the iteration
range is unchanged. All six existing call sites in
net/sunrpc/xprtrdma/svc_rdma_recvfrom.c and
net/sunrpc/xprtrdma/svc_rdma_rw.c remain correct under the new bound,
so no caller changes are needed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 78147ca8b4a9b6cf0e597ddd6bf17959e08376c2
Version < 1e2e3481e39103a386b86be1c33eaef97cbdf16e
Status affected
Version 78147ca8b4a9b6cf0e597ddd6bf17959e08376c2
Version < 3a78b841879c2a3243f74edc514236fb2907167f
Status affected
Version 78147ca8b4a9b6cf0e597ddd6bf17959e08376c2
Version < 06d0390c37fa6714624af771bd72bbf1a7ed9bb1
Status affected
Version 78147ca8b4a9b6cf0e597ddd6bf17959e08376c2
Version < 9c5a03c3dc505c0295339b0a1b9e4fe36447e482
Status affected
Version 78147ca8b4a9b6cf0e597ddd6bf17959e08376c2
Version < a1c954ca4977a4e6ec73ef92fe48073ec54f9fc8
Status affected
Version 78147ca8b4a9b6cf0e597ddd6bf17959e08376c2
Version < 6d33a7e6bf6c6b293a266a617201285a1ad32c56
Status affected
Version 78147ca8b4a9b6cf0e597ddd6bf17959e08376c2
Version < b7713a784c59515d0aba558c8f5df6a0164dd3a9
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.11
Status affected
Version 0
Version < 5.11
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.388
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9c5a03c3dc505c0295339b0a1b9e4fe36447e482
https://git.kernel.org/stable/c/a1c954ca4977a4e6ec73ef92fe48073ec54f9fc8
https://git.kernel.org/stable/c/6d33a7e6bf6c6b293a266a617201285a1ad32c56
https://git.kernel.org/stable/c/b7713a784c59515d0aba558c8f5df6a0164dd3a9
https://git.kernel.org/stable/c/06d0390c37fa6714624af771bd72bbf1a7ed9bb1
https://git.kernel.org/stable/c/1e2e3481e39103a386b86be1c33eaef97cbdf16e
https://git.kernel.org/stable/c/3a78b841879c2a3243f74edc514236fb2907167f