CVE-2026-89531

Summary

In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Reject connection when transport allocation fails

handle_connect_req() returns without action when svc_rdma_create_xprt() fails to allocate the new transport. The CM core returns 0 for CONNECT_REQUEST events, so it does not destroy the new rdma_cm_id. Each allocation failure under memory pressure leaks one rdma_cm_id, and a remote peer driving connection attempts can amplify this.

Reject the connection by returning a non-zero status from the CM event handler, which tells the CM core to destroy the orphaned cm_id.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux377f9b2f4529e0ac702fd7b91e216afd0adc959e < 6e21754bbf75075f3fee1cebc79f3417364235ecaffected
LinuxLinux377f9b2f4529e0ac702fd7b91e216afd0adc959e < 3cf372cec7ab2cd8c6002bf775cc14d90ccb098baffected
LinuxLinux377f9b2f4529e0ac702fd7b91e216afd0adc959e < 1f6a14c142fee4778c32709d1d54595c2e2b7991affected
LinuxLinux377f9b2f4529e0ac702fd7b91e216afd0adc959e < 0944462247dcb7de7622cdaaadf5f05c52707dabaffected
LinuxLinux2.6.25affected
LinuxLinux0 < 2.6.25unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References