svcrdma: Reject inline replies that overflow the pull-up buffer
Summary
| CVE | CVE-2026-89530 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:19:35 UTC |
| Updated | 2026-09-11 20:19:35 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
svcrdma: Reject inline replies that overflow the pull-up buffer
An RPC-over-RDMA client can request a reply, such as an NFS READ
payload, without providing a Write list or a Reply chunk to carry
it. When such a reply needs more scatter/gather entries than the
device's Send Queue supports, svc_rdma_pull_up_needed() selects
pull-up and svc_rdma_pull_up_reply_msg() linearizes the whole
reply into sctxt->sc_xprt_buf. That buffer is only sc_max_req_size
bytes, while the reply on this path is bounded only by the client's
request, so svc_rdma_xb_linearize() copies past the end of the
buffer and corrupts adjacent slab memory. The oversized length is
then stored in sc_sges[0].length and posted, so the device also
reads beyond the mapped region.
The SGE-exhaustion branch is the only pull-up path that can exceed
the buffer: the threshold branch pulls up only replies smaller
than RPCRDMA_PULLUP_THRESH, and replies that fit the device's SGE
budget are sent directly without linearization. Make
svc_rdma_pull_up_needed() report -E2BIG when the reply it would
pull up cannot fit sc_max_req_size, and fail the request with
ERR_CHUNK as RFC 8166 Section 4.5.3 directs rather than dropping
the connection.
The helper no longer answers a simple yes/no question: it now
reports pull-up, no pull-up, or -E2BIG for a reply too large to
linearize. Rename svc_rdma_pull_up_needed() to
svc_rdma_check_pull_up() so its name no longer implies a boolean
predicate. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected e248aa7be86e8179f20ac0931774ecd746f3f5bf fcd91b9957462d398792201c239dffaeff1cc8b2 git |
Not specified |
| CNA |
Linux |
Linux |
affected e248aa7be86e8179f20ac0931774ecd746f3f5bf 1949dd1576f7a8aa161b1330c6125df9d53046d5 git |
Not specified |
| CNA |
Linux |
Linux |
affected e248aa7be86e8179f20ac0931774ecd746f3f5bf 8ec60eb51fae37cd3d334ff26e4a7d6fb21ff7cf git |
Not specified |
| CNA |
Linux |
Linux |
affected e248aa7be86e8179f20ac0931774ecd746f3f5bf 0fbe20dfe74b783d255bf389a6ea77aa25dc7860 git |
Not specified |
| CNA |
Linux |
Linux |
affected 9b65b18f817d9ada2bf67351f24bdcce6789a0bb git |
Not specified |
| CNA |
Linux |
Linux |
affected d564356e1919d1178568c19af410cfc1a9076663 git |
Not specified |
| CNA |
Linux |
Linux |
affected 4.19.22 4.20 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 4.20.9 4.21 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 5.0 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.0 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.109 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.50 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.4 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/fcd91b9957462d398792201c239dffaeff1cc8b2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/1949dd1576f7a8aa161b1330c6125df9d53046d5 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/8ec60eb51fae37cd3d334ff26e4a7d6fb21ff7cf |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0fbe20dfe74b783d255bf389a6ea77aa25dc7860 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.