CRITICAL Introduced in 5.11
svcrdma ReadChunk OOB
CVE-2026-89526
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI9.1CRITICAL
01Description
In the Linux kernel, the following vulnerability has been resolved: svcrdma: Validate Read chunk positions before reconstruction The RPC/RDMA Read chunk position field is supplied by the remote client and stored verbatim in the parsed chunk list. xdr_count_read_segments() checks only 4-byte alignment; it never compares the position against the received inline body length. In the single-chunk path, svc_rdma_read_complete_one() splits the head and tail kvecs at ch_position. A position past the inline body underflows the tail length, exposing adjacent slab memory to the upper XDR decoder. In the multi-chunk path, svc_rdma_read_multiple_chunks() computes gap lengths between chunks as unsigned subtractions from ch_position. Overlapping Read chunks cause these subtractions to underflow. A final position past the inline body likewise underflows the trailing gap length. svc_rdma_copy_inline_range() then copies past the receive buffer into request pages that are returned to the client through the Reply channel. Bound inline-range copies in svc_rdma_copy_inline_range() against the decoded inline RPC body saved in rc_saved_arg. Reject a single Read chunk positioned beyond that body, and reject multi-chunk lists where accumulated read bytes exceed the next chunk's position. Apply the same position and overlap checks in the call-chunk interleaving path.
02KernelScan AI Analysis
Risk summary
A remote, unauthenticated attacker can send a crafted RPC/RDMA request with an out-of-range Read chunk position to an NFS-over-RDMA server, causing the kernel to copy memory beyond the receive buffer. This leaks kernel slab memory back to the attacker through the RPC reply and can cause resource exhaustion from unbounded page allocation. Any host running the svcrdma module is affected.
Vulnerability analysis
The RPC/RDMA server stores the Read chunk position field from a remote client without comparing it against the actual length of the received inline body. When reconstructing the RPC message, unsigned arithmetic on an out-of-range position underflows, causing the kernel to split buffers or copy data starting past the end of the receive buffer. Adjacent slab memory is then exposed to the upper XDR decoder or copied into request pages that are returned to the client through the RPC reply channel. The fix bounds all inline-range copies against the decoded inline body length saved during receive, and rejects single Read chunks positioned beyond that body as well as multi-chunk lists where accumulated read bytes exceed the next chunk's position or chunks overlap. Any host running NFS over RDMA with the svcrdma module loaded is reachable by a remote, unauthenticated attacker at the transport layer.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 5.11 | 6.12.109 | 5ab3f6d882fe |
| 6.18 | 5.11 | 6.18.50 | f84ec84d8d4b |
| 7.2 | 5.11 | 7.2.4 | 577097455d08 |
| mainline | 5.11 | 7.3-rc1 | 3779b7b9e7d1 |