CVE-2026-89530High· 7.0▾ TwilightA flaw was found in the Linux kernel's svcrdma component, which handles network communication using Remote Direct Memory Access (RDMA). A remote attacker can send a specially crafted network reply that is larger than expected. This can cau…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 8.1
0.2% → 0.5%
— → 8.1
none → high
— → 9.8
none → critical
9.8 → 8.1
critical → high
8.1 → 9.8
high → critical
9.8 → 8.1
critical → high
Last analysed / modified upstream
8.1 → 7
A flaw was found in the Linux kernel's svcrdma component, which handles network communication using Remote Direct Memory Access (RDMA). A remote attacker can send a specially crafted network reply that is larger than expected. This can cause the system to write data beyond the intended memory area, leading to memory corruption. This vulnerability could allow an attacker to cause a denial of service or potentially execute arbitrary code.
kernel: svcrdma: Reject inline replies that overflow the pull-up buffer — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-18.
Affected:
No fix planned:
Affected
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80986High· 7.0kernel: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages (CVE-2026-80986)
CVE-2026-81002High· 7.0kernel: xdp: fix zero-copy frame layout (CVE-2026-81002)
CVE-2026-89482High· 7.0kernel: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone (CVE-2026-89482)
CVE-2026-80944High· 7.0kernel: wifi: mwifiex: Detach sync cmd buffer on interrupted wait (CVE-2026-80944)
CVE-2026-80951High· 7.0kernel: i3c: master: svc: bound IBI payload to the requested max_payload_len (CVE-2026-80951)
CVE-2026-81000High· 7.8kernel: net: tun: bound receive headroom (CVE-2026-81000)