Answer in brief
CVE-2026-89526 records a Unknown severity vulnerability in svcrdma: Validate Read chunk positions before reconstruction. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d96962e6d0e281bab6a48e83b42f5dce6eb28bf4 <5ab3f6d882fe07ae5e61d0bcfeea00b9409155c2 || >=d96962e6d0e281bab6a48e83b42f5dce6eb28bf4 <f84ec84d8d4bc65f9ae23372570349687f66fa39 || >=d96962e6d0e281bab6a48e83b42f5dce6eb28bf4 <577097455d084610fc31e91e6a61c5793b6f04ba || >=d96962e6d0e281bab6a48e83b42f5dce6eb28bf4 <3779b7b9e7d1c8ba4738f9d327de3b0288cefe9b | 5ab3f6d882fe07ae5e61d0bcfeea00b9409155c2, f84ec84d8d4bc65f9ae23372570349687f66fa39, 577097455d084610fc31e91e6a61c5793b6f04ba, 3779b7b9e7d1c8ba4738f9d327de3b0288cefe9b |
| Linux/Linuxgeneric | 5.11 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: svcrdma: Validate Read chunk positions before reconstruction The RPC/RDMA Read chunk position field is supplied by the remote client and stored verbatim in the parsed chunk list. xdr_count_read_segments() checks only 4-byte alignment; it never compares the position against the received inline body length. In the single-chunk path, svc_rdma_read_complete_one() splits the head and tail kvecs at ch_position. A position past the inline body underflows the tail length, exposing adjacent slab memory to the upper XDR decoder. In the multi-chunk path, svc_rdma_read_multiple_chunks() computes gap lengths between chunks as unsigned subtractions from ch_position. Overlapping Read chunks cause these subtractions to underflow. A final position past the inline body likewise underflows the trailing gap length. svc_rdma_copy_inline_range() then copies past the receive buffer into request pages that are returned to the client through the Reply channel. Bound inline-range copies in svc_rdma_copy_inline_range() against the decoded inline RPC body saved in rc_saved_arg. Reject a single Read chunk positioned beyond that body, and reject multi-chunk lists where accumulated read bytes exceed the next chunk's position. Apply the same position and overlap checks in the call-chunk interleaving path.
Quoted source text, attributed separately from HOL analysis.