Memory Registration Vulnerability in Linux Kernel Affecting RDMA Products
CVE-2026-93264
What is CVE-2026-93264?
A vulnerability exists in the Linux kernel's RDMA component concerning the improper calculation of the length of a chunk list during the memory registration of pages in indirect Private Buffer Lists (PBL). This issue arises when the number of pages is a multiple of predefined chunk constants, leading to the last chunk being incorrectly reported as empty. Consequently, devices may reject valid memory registrations, resulting in potential denial of service for RDMA operations. The fix involves ensuring that chunk length calculations are only performed when the conditions are not met. This prevents further complications, such as out-of-bounds access in chunk arrays.
Affected Version(s)
Linux 40909f664d279765af430acc5db348a0b71c9b0a < 665cd418b8561a099c3854443f8ad8ae751b72a0
Linux 40909f664d279765af430acc5db348a0b71c9b0a < 932e5684906a090644a9061fae2d254041c3b8f2
Linux 40909f664d279765af430acc5db348a0b71c9b0a < 489b28f2377afa70c18c45b06a6387f3d39bb123