{"id":"CVE-2026-89526","title":"kernel: svcrdma: Validate Read chunk positions before reconstruction (CVE-2026-89526)","summary":"A flaw was found in the `svcrdma` component of the Linux kernel. A remote attacker can exploit this vulnerability by supplying a crafted `RPC/RDMA Read chunk position` field that is not properly validated against the received inline body l…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-125","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-16","sourceUpdated":"2026-09-16T09:38:34+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89526.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89526.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89526"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532309"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89526"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89526"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89526.mbox"},{"url":"https://git.kernel.org/stable/c/3779b7b9e7d1c8ba4738f9d327de3b0288cefe9b"},{"url":"https://git.kernel.org/stable/c/577097455d084610fc31e91e6a61c5793b6f04ba"},{"url":"https://git.kernel.org/stable/c/5ab3f6d882fe07ae5e61d0bcfeea00b9409155c2"},{"url":"https://git.kernel.org/stable/c/f84ec84d8d4bc65f9ae23372570349687f66fa39"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00626,"epssPercentile":0.4864,"scores":{"vendor":8.1,"cna":9.8},"ingestedAt":"2026-09-14T15:23:07.475Z","slug":"CVE-2026-89526","body":"## Overview\n\nA flaw was found in the `svcrdma` component of the Linux kernel. A remote attacker can exploit this vulnerability by supplying a crafted `RPC/RDMA Read chunk position` field that is not properly validated against the received inline body length. This can lead to an underflow, exposing adjacent slab memory or allowing data to be copied past the receive buffer into request pages. The most significant impact is information disclosure, potentially leading to memory corruption.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89526.json)\n\n**kernel: svcrdma: Validate Read chunk positions before reconstruction** — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-16.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":205473,"id":"CVE-2026-89526","ts":1789576721434,"field":"cvss","old":"8.1","new":"7"},{"seq":203027,"id":"CVE-2026-89526","ts":1789403733402,"field":"cvss","old":"9.8","new":"8.1"},{"seq":203026,"id":"CVE-2026-89526","ts":1789403733402,"field":"severity","old":"critical","new":"high"},{"seq":197971,"id":"CVE-2026-89526","ts":1789384321202,"field":"cvss","old":"8.1","new":"9.8"},{"seq":197970,"id":"CVE-2026-89526","ts":1789384321202,"field":"severity","old":"high","new":"critical"},{"seq":183772,"id":"CVE-2026-89526","ts":1789356677320,"field":"cvss","old":"9.8","new":"8.1"},{"seq":183771,"id":"CVE-2026-89526","ts":1789356677320,"field":"severity","old":"critical","new":"high"},{"seq":153318,"id":"CVE-2026-89526","ts":1789285350023,"field":"cvss","old":null,"new":"9.8"},{"seq":153317,"id":"CVE-2026-89526","ts":1789285350023,"field":"severity","old":"none","new":"critical"},{"seq":147416,"id":"CVE-2026-89526","ts":1789270210824,"field":"cvss","old":null,"new":"8.1"},{"seq":147415,"id":"CVE-2026-89526","ts":1789270210824,"field":"severity","old":"none","new":"high"},{"seq":109154,"id":"CVE-2026-89526","ts":1789183730524,"field":"cvss","old":null,"new":"8.1"},{"seq":109153,"id":"CVE-2026-89526","ts":1789183730524,"field":"severity","old":"none","new":"high"}]}