← All Advisories

CVE-2026-93228

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-93228

Key Details

CVECVE-2026-93228
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Reject Write/Reply chunks with segcount 0

A peer can send a Write or Reply chunk whose segcount field is zero.

xdr_check_write_chunk() only rejects segcount > rc_maxpages, so zero

passes the range check, and xdr_inline_decode(stream, 0) returns the

current (non-NULL) cursor without advancing. The function returns

true and pcl_alloc_write() then links a struct svc_rdma_chunk with

ch_segcount == 0 onto rc_write_pcl or rc_reply_pcl.

An earlier patch in this series made pcl_for_each_segment() safe for

ch_segcount == 0, so this no longer drives the memory walk it used

to. Rejecting the malformed frame at the decode boundary is still

worthwhile as defense in depth: it keeps degenerate zero-segment

chunks off the parsed chunk lists entirely, so any future consumer

that walks ch_segments directly cannot observe one, and it makes the

zero-floor easy to backport to trees where the macro change is more

intrusive. RFC 8166 has no meaning for a Write/Reply chunk that

describes no remote buffer, so no legitimate client is affected.

xdr_check_reply_chunk() funnels Reply chunks through

xdr_check_write_chunk() and inherits the same rejection.

pcl_alloc_write() also links each chunk onto the parsed chunk list

before filling its segment array. If a future change weakens the

segcount-0 rejection, an incomplete chunk is visible to consumers

during the fill loop. Reorder so that list_add_tail() follows the

segment fill loop, ensuring only fully-populated chunks appear on

the list. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93228
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93228