CVE-2026-89531
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
svcrdma: Reject connection when transport allocation fails
handle_connect_req() returns without action when svc_rdma_create_xprt() fails to allocate the new transport. The CM core returns 0 for CONNECT_REQUEST events, so it does not destroy the new rdma_cm_id. Each allocation failure under memory pressure leaks one rdma_cm_id, and a remote peer driving connection attempts can amplify this.
Reject the connection by returning a non-zero status from the CM event handler, which tells the CM core to destroy the orphaned cm_id.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 377f9b2f4529e0ac702fd7b91e216afd0adc959e < 6e21754bbf75075f3fee1cebc79f3417364235ec | affected |
| Linux | Linux | 377f9b2f4529e0ac702fd7b91e216afd0adc959e < 3cf372cec7ab2cd8c6002bf775cc14d90ccb098b | affected |
| Linux | Linux | 377f9b2f4529e0ac702fd7b91e216afd0adc959e < 1f6a14c142fee4778c32709d1d54595c2e2b7991 | affected |
| Linux | Linux | 377f9b2f4529e0ac702fd7b91e216afd0adc959e < 0944462247dcb7de7622cdaaadf5f05c52707dab | affected |
| Linux | Linux | 2.6.25 | affected |
| Linux | Linux | 0 < 2.6.25 | unaffected |
| Linux | Linux | 6.12.109 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/6e21754bbf75075f3fee1cebc79f3417364235ec
- https://git.kernel.org/stable/c/3cf372cec7ab2cd8c6002bf775cc14d90ccb098b
- https://git.kernel.org/stable/c/1f6a14c142fee4778c32709d1d54595c2e2b7991
- https://git.kernel.org/stable/c/0944462247dcb7de7622cdaaadf5f05c52707dab
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.