{"id":"CVE-2026-89529","title":"kernel: svcrdma: Reject oversized Read segments at decode time (CVE-2026-89529)","summary":"A flaw was found in the Linux kernel's svcrdma component, which handles Remote Procedure Call over Remote Direct Memory Access (RPC/RDMA) Read operations. This vulnerability occurs because the Read list decoder does not properly validate t…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-772","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","affected":["enterprise_linux 10","enterprise_linux 6"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T08:50:40+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89529.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89529.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89529"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532020"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89529"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89529"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89529.mbox"},{"url":"https://git.kernel.org/stable/c/5120fe54e0e2f5b62797a432115cc61d61117a5b"},{"url":"https://git.kernel.org/stable/c/af6f0e06bed818ee7fc8b869915964410020a1c5"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00189,"epssPercentile":0.08789,"ingestedAt":"2026-09-14T11:11:19.886Z","slug":"CVE-2026-89529","body":"## Overview\n\nA flaw was found in the Linux kernel's svcrdma component, which handles Remote Procedure Call over Remote Direct Memory Access (RPC/RDMA) Read operations. This vulnerability occurs because the Read list decoder does not properly validate the lengths of incoming data segments. An attacker could send an oversized Read segment, leading to excessive memory allocation and a subsequent resource leak. This resource exhaustion could potentially result in a Denial of Service (DoS) condition, making the system unavailable.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89529.json)\n\n**kernel: svcrdma: Reject oversized Read segments at decode time** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 10\n\nNot affected:\n\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nOut of support scope","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":202800,"id":"CVE-2026-89529","ts":1789403723510,"field":"cvss","old":null,"new":"7"},{"seq":202799,"id":"CVE-2026-89529","ts":1789403723510,"field":"severity","old":"none","new":"high"},{"seq":109618,"id":"CVE-2026-89529","ts":1789183732668,"field":"cvss","old":null,"new":"5.9"},{"seq":109617,"id":"CVE-2026-89529","ts":1789183732668,"field":"severity","old":"none","new":"medium"}]}