{"id":"CVE-2026-89530","title":"kernel: svcrdma: Reject inline replies that overflow the pull-up buffer (CVE-2026-89530)","summary":"A flaw was found in the Linux kernel's svcrdma component, which handles network communication using Remote Direct Memory Access (RDMA). A remote attacker can send a specially crafted network reply that is larger than expected. This can cau…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-787","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4","enterprise_linux 6"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T21:58:18+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89530.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89530.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89530"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532218"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89530"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89530"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89530.mbox"},{"url":"https://git.kernel.org/stable/c/0fbe20dfe74b783d255bf389a6ea77aa25dc7860"},{"url":"https://git.kernel.org/stable/c/1949dd1576f7a8aa161b1330c6125df9d53046d5"},{"url":"https://git.kernel.org/stable/c/8ec60eb51fae37cd3d334ff26e4a7d6fb21ff7cf"},{"url":"https://git.kernel.org/stable/c/fcd91b9957462d398792201c239dffaeff1cc8b2"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00463,"epssPercentile":0.39388,"scores":{"vendor":7,"cna":9.8},"ingestedAt":"2026-09-14T15:23:07.474Z","slug":"CVE-2026-89530","body":"## Overview\n\nA flaw was found in the Linux kernel's svcrdma component, which handles network communication using Remote Direct Memory Access (RDMA). A remote attacker can send a specially crafted network reply that is larger than expected. This can cause the system to write data beyond the intended memory area, leading to memory corruption. This vulnerability could allow an attacker to cause a denial of service or potentially execute arbitrary code.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 6 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89530.json)\n\n**kernel: svcrdma: Reject inline replies that overflow the pull-up buffer** — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n- Red Hat Enterprise Linux 6\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":206930,"id":"CVE-2026-89530","ts":1789749704427,"field":"cvss","old":"8.1","new":"7"},{"seq":203023,"id":"CVE-2026-89530","ts":1789403733387,"field":"cvss","old":"9.8","new":"8.1"},{"seq":203022,"id":"CVE-2026-89530","ts":1789403733387,"field":"severity","old":"critical","new":"high"},{"seq":197965,"id":"CVE-2026-89530","ts":1789384321178,"field":"cvss","old":"8.1","new":"9.8"},{"seq":197964,"id":"CVE-2026-89530","ts":1789384321178,"field":"severity","old":"high","new":"critical"},{"seq":183766,"id":"CVE-2026-89530","ts":1789356677296,"field":"cvss","old":"9.8","new":"8.1"},{"seq":183765,"id":"CVE-2026-89530","ts":1789356677296,"field":"severity","old":"critical","new":"high"},{"seq":153322,"id":"CVE-2026-89530","ts":1789285350040,"field":"cvss","old":null,"new":"9.8"},{"seq":153321,"id":"CVE-2026-89530","ts":1789285350040,"field":"severity","old":"none","new":"critical"},{"seq":147596,"id":"CVE-2026-89530","ts":1789270211532,"field":"cvss","old":null,"new":"8.1"},{"seq":147595,"id":"CVE-2026-89530","ts":1789270211532,"field":"severity","old":"none","new":"high"},{"seq":109348,"id":"CVE-2026-89530","ts":1789183731559,"field":"cvss","old":null,"new":"8.1"},{"seq":109347,"id":"CVE-2026-89530","ts":1789183731559,"field":"severity","old":"none","new":"high"}]}