All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-89529: svcrdma: Reject oversized Read segments at decode time
@ 2026-09-11 19:43 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:43 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Reject oversized Read segments at decode time

The RPC/RDMA Read list decoder stores wire-supplied segment
lengths without validation. xdr_count_read_segments() checks
4-byte alignment for non-zero position values but does not
cap the segment length.

An oversized rs_length reaches svc_rdma_build_read_segment(),
which derives nr_bvec from it and can drive a large dynamic
bvec allocation before verifying that enough rq_pages remain.
If the post-allocation page-overrun guard fires, the freshly
acquired rw context is not returned, leaking the resource.

Reject any segment whose length exceeds the receive context's
page budget during Read list decoding, consistent with how
xdr_check_write_chunk() bounds Write segment counts against
rc_maxpages. Also return the rw context on the existing
post-allocation overrun path in svc_rdma_build_read_segment(),
keeping that defensive guard balanced.

The Linux kernel CVE team has assigned CVE-2026-89529 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 7.0 with commit 5ee62b4a91137557ee4b09d1604f1dfd0b4344a8 and fixed in 7.2.4 with commit 5120fe54e0e2f5b62797a432115cc61d61117a5b
	Issue introduced in 7.0 with commit 5ee62b4a91137557ee4b09d1604f1dfd0b4344a8 and fixed in 7.3-rc1 with commit af6f0e06bed818ee7fc8b869915964410020a1c5

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-89529
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	net/sunrpc/xprtrdma/svc_rdma_recvfrom.c
	net/sunrpc/xprtrdma/svc_rdma_rw.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/5120fe54e0e2f5b62797a432115cc61d61117a5b
	https://git.kernel.org/stable/c/af6f0e06bed818ee7fc8b869915964410020a1c5

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-11 19:54 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:43 CVE-2026-89529: svcrdma: Reject oversized Read segments at decode time Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.