Memory Registration Vulnerability in Linux Kernel Affecting RDMA Products
CVE-2026-93264

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-93264?

A vulnerability exists in the Linux kernel's RDMA component concerning the improper calculation of the length of a chunk list during the memory registration of pages in indirect Private Buffer Lists (PBL). This issue arises when the number of pages is a multiple of predefined chunk constants, leading to the last chunk being incorrectly reported as empty. Consequently, devices may reject valid memory registrations, resulting in potential denial of service for RDMA operations. The fix involves ensuring that chunk length calculations are only performed when the conditions are not met. This prevents further complications, such as out-of-bounds access in chunk arrays.

Affected Version(s)

Linux 40909f664d279765af430acc5db348a0b71c9b0a < 665cd418b8561a099c3854443f8ad8ae751b72a0

Linux 40909f664d279765af430acc5db348a0b71c9b0a < 932e5684906a090644a9061fae2d254041c3b8f2

Linux 40909f664d279765af430acc5db348a0b71c9b0a < 489b28f2377afa70c18c45b06a6387f3d39bb123

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.