CVE-2026-93228
9.1 CRITICALPublished 2026-09-24 · Updated 2026-09-25
AI risk analysis
- Summary
- The flaw allows a peer to send a Write or Reply chunk with a segcount of 0, which is not properly rejected, potentially leading to memory issues or denial of service.
- Exploitability
- Exploitation requires the ability to send malformed RDMA frames, which is generally difficult without control over the network or kernel.
- Blast radius
- If exploited, it could lead to memory corruption or denial of service for the affected system.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the Linux kernel version 6.2.11 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Write/Reply chunks with segcount 0 A peer can send a Write or Reply chunk whose segcount field is zero. xdr_check_write_chunk() only rejects segcount > rc_maxpages, so zero passes the range check, and xdr_inline_decode(stream, 0) returns the current (non-NULL) cursor without advancing. The function returns true and pcl_alloc_write() then links a struct svc_rdma_chunk with ch_segcount == 0 onto rc_write_pcl or rc_reply_pcl. An earlier patch in this series made pcl_for_each_segment() safe for ch_segcount == 0, so this no longer drives the memory walk it used to. Rejecting the malformed frame at the decode boundary is still worthwhile as defense in depth: it keeps degenerate zero-segment chunks off the parsed chunk lists entirely, so any future consumer that walks ch_segments directly cannot observe one, and it makes the zero-floor easy to backport to trees where the macro change is more intrusive. RFC 8166 has no meaning for a Write/Reply chunk that describes no remote buffer, so no legitimate client is affected. xdr_check_reply_chunk() funnels Reply chunks through xdr_check_write_chunk() and inherits the same rejection. pcl_alloc_write() also links each chunk onto the parsed chunk list before filling its segment array. If a future change weakens the segcount-0 rejection, an incomplete chunk is visible to consumers during the fill loop. Reorder so that list_add_tail() follows the segment fill loop, ensuring only fully-populated chunks appear on the list.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-100075
- HIGHCVE-2026-91018PoC
- HIGHCVE-2026-10575
- CRITICALCVE-2026-10747
- CRITICALCVE-2026-10858
- HIGHCVE-2026-11375
- HIGHCVE-2026-11378
- HIGHCVE-2026-11381
Related by shared AI tags and CWE weakness class. Browse the full archive.