{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89528","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.719Z","datePublished":"2026-09-11T19:44:08.514Z","dateUpdated":"2026-09-13T06:30:25.969Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:30:25.969Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Reject Read lists that exceed the page budget\n\nIndividual Read segment lengths are validated at decode time, but\nnothing prevents a requester from sending multiple segments whose\ncumulative length exceeds the rq_pages array budget. When one\nsegment fills the page array exactly, the runtime guard in\nsvc_rdma_build_read_segment() is bypassed because len reaches zero.\nA subsequent segment then accesses the NULL sentinel slot at\nrq_pages[rq_maxpages], resulting in a NULL pointer dereference during\nDMA mapping.\n\nAccumulate pages across all Read segments and reject the message at\ndecode time when the total would overflow the page budget."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - svcrdma is nfsd's RPC-over-RDMA server transport; a remote peer reaches svc_rdma_recvfrom() by sending a Call with a Read list on an enabled NFS/RDMA listener over routable RoCEv2 or iWARP.\nAC:L - The attacker fully controls Read-segment lengths in the transport header and can deterministically fill rq_pages exactly, then send a further segment so the len==0 overrun guard is skipped and the NULL sentinel is DMA-mapped, with no race or uncontrollable layout.\nPR:N - xdr_count_read_segments() and svc_rdma_build_read_segment() run in svc_rdma_recvfrom() while assembling the transport message, before svc_process() performs RPC or NFS authentication, and RDMA CM accept has no credential check.\nUI:N - Sending a crafted RPC-over-RDMA message with an over-budget Read list is sufficient; no victim mount, click, or other user action is required.\nS:U - The NULL dereference oops stays in the host kernel that owns nfsd/svcrdma; this is not a VM, IOMMU, or sandbox escape.\nC:N - The fault is a NULL pointer dereference of the rq_pages[rq_maxpages] sentinel during DMA mapping; the access faults immediately and does not disclose kernel memory.\nI:N - The sentinel slot is a guaranteed NULL page pointer, not an out-of-bounds page used as a write destination; DMA mapping aborts on the NULL page without an arbitrary-write or control-flow hijack primitive.\nA:H - DMA mapping the NULL sentinel produces a kernel oops or panic that an unauthenticated NFS/RDMA peer can trigger repeatedly."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/xprtrdma/svc_rdma_recvfrom.c"],"versions":[{"version":"026d958b38c628a1b4ced534808945365e2747a5","lessThan":"1a3af2262cb384112ef38632de4690682be528b4","status":"affected","versionType":"git"},{"version":"026d958b38c628a1b4ced534808945365e2747a5","lessThan":"465f511f59a0fa7a80d5d1073c4b24f28ea38f58","status":"affected","versionType":"git"},{"version":"026d958b38c628a1b4ced534808945365e2747a5","lessThan":"0ca487abb3bdf581851664b5db21f364caf57682","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/xprtrdma/svc_rdma_recvfrom.c"],"versions":[{"version":"4.13","status":"affected"},{"version":"0","lessThan":"4.13","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.13","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.13","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.13","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1a3af2262cb384112ef38632de4690682be528b4"},{"url":"https://git.kernel.org/stable/c/465f511f59a0fa7a80d5d1073c4b24f28ea38f58"},{"url":"https://git.kernel.org/stable/c/0ca487abb3bdf581851664b5db21f364caf57682"}],"title":"svcrdma: Reject Read lists that exceed the page budget","x_generator":{"engine":"bippy-1.2.0"}}}}