From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2D7E1584944 for ; Fri, 11 Sep 2026 19:54:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156480; cv=none; b=Y1CC/md5UvGtAGyYmF91Ig7IvM8zPIQnbJ8Eb2bj/cl84YBVAPTwxQSDDYUvHquZ+G8gVV0EI59rXgIhhEXdQANm0u85uAmfjl9Ihduu28oo/VUYhqWOu8ix0tbvpQDf7/hNr9gYl/ueHw0AKpUgB9Tjhr87KVictj4eQkO2wD4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156480; c=relaxed/simple; bh=xj8mc9ZkO/CIbNksi1MxUOiKhiCmD9sk5Meak76n9tk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=WPhWmE/pOpe+fuXrL4CvQsvkNjp6LFg0N96UbDw3UEFMQdermkwLvZA9VdoBfGN0YD7deECEBYpoxqdkZS9u9mXX9fVBreHKzD3+kKV2Es60/6q8NLhc4BEcKVzFKAOEzXFrK7tmwp58ObevjpJKCq0/02fuFmyhudvh0HiDQSs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=nWbIXWro; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="nWbIXWro" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 63B711F000FF; Fri, 11 Sep 2026 19:54:30 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156470; bh=/scxoatI1Q140roHpfcf+BdXbdpiKs9Tlm+QyZb2amA=; h=From:To:Cc:Subject:Date:Reply-To; b=nWbIXWro3trE1jRz9kFte3+ryuxb5b/0ei82r1dLobMGKox9/6uz/bZenqQG3SiIn vIwU4a7KgJCsOXesmm8wGU8+RM+cVTYuRhvrK8nggbeOmnFKYvBe01srdpRBy2RJg4 3AMWpCw9bRaoVAWd7xBQL6t5nJl8YaF4O858f97M= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89529: svcrdma: Reject oversized Read segments at decode time Date: Fri, 11 Sep 2026 21:43:38 +0200 Message-ID: <2026091116-CVE-2026-89529-6601@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2677; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=zeCst7IAlkvbcuKsLgVd/uK+7vlw5XCmLdU+cpzz+MY=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLImO2OE04ldziqTEz4OfqS2omsYscXPOuVjZ7BrhPu fdHTOR3RywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAExErYFhvrdGx6sXU70n/H4s wd35lbNFpCBsEsN8n1D9tClFpztSfdob5P6I/kt7MDMRAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject oversized Read segments at decode time The RPC/RDMA Read list decoder stores wire-supplied segment lengths without validation. xdr_count_read_segments() checks 4-byte alignment for non-zero position values but does not cap the segment length. An oversized rs_length reaches svc_rdma_build_read_segment(), which derives nr_bvec from it and can drive a large dynamic bvec allocation before verifying that enough rq_pages remain. If the post-allocation page-overrun guard fires, the freshly acquired rw context is not returned, leaking the resource. Reject any segment whose length exceeds the receive context's page budget during Read list decoding, consistent with how xdr_check_write_chunk() bounds Write segment counts against rc_maxpages. Also return the rw context on the existing post-allocation overrun path in svc_rdma_build_read_segment(), keeping that defensive guard balanced. The Linux kernel CVE team has assigned CVE-2026-89529 to this issue. Affected and fixed versions =========================== Issue introduced in 7.0 with commit 5ee62b4a91137557ee4b09d1604f1dfd0b4344a8 and fixed in 7.2.4 with commit 5120fe54e0e2f5b62797a432115cc61d61117a5b Issue introduced in 7.0 with commit 5ee62b4a91137557ee4b09d1604f1dfd0b4344a8 and fixed in 7.3-rc1 with commit af6f0e06bed818ee7fc8b869915964410020a1c5 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89529 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/sunrpc/xprtrdma/svc_rdma_recvfrom.c net/sunrpc/xprtrdma/svc_rdma_rw.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/5120fe54e0e2f5b62797a432115cc61d61117a5b https://git.kernel.org/stable/c/af6f0e06bed818ee7fc8b869915964410020a1c5