Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93264— RDMA/efa: Fix PBL chunk length computation

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: RDMA/efa:修复 PBL 块长度计算错误 在注册内存区域(MR)时,创建 PBL(物理块列表)过程中,如果使用的是间接 PBL,系统会创建一个块列表来存储 PBL 页的指针。每个块的大小为 4KB,可容纳 510 个地址(EFA_PTRS_PER_CHUNK),并在末尾包含一个 12 字节的控制缓冲区,用于保存下一块的指针及其长度。 当 PBL 的页数恰好是 EFA_PTRS_PER_CHUNK(510)的整数倍时,最后一个块的长度会被错误地计算为 0,尽管该块实

AI Predicted 7.8 Difficulty: Moderate EPSS 0.20% · P9

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 40909f664d279765af430acc5db348a0b71c9b0a< 665cd418b8561a099c3854443f8ad8ae751b72a0 affected
40909f664d279765af430acc5db348a0b71c9b0a< 932e5684906a090644a9061fae2d254041c3b8f2 affected
40909f664d279765af430acc5db348a0b71c9b0a< 489b28f2377afa70c18c45b06a6387f3d39bb123 affected
40909f664d279765af430acc5db348a0b71c9b0a< aadf3f9b5edb7f0a77e9172b237d2e07c754829c affected
40909f664d279765af430acc5db348a0b71c9b0a< 3982714e15512b83115897806dacc94899683420 affected
40909f664d279765af430acc5db348a0b71c9b0a< da7805f0211af19968584e621074f253ac07dba7 affected
40909f664d279765af430acc5db348a0b71c9b0a< 1d4b5902773475fc97151379b7e5f09cad0fa57b affected
40909f664d279765af430acc5db348a0b71c9b0a< 229b42d7450c1cf96f45ec39ebb69211b06bc036 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93264

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RDMA/efa: Fix PBL chunk length computation
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/efa: Fix PBL chunk length computation On register MR, when creating the PBL, if it's an indirect PBL we create a chunk list to hold the PBL pages pointers. Each chunk is 4KB in size and can hold 510 addresses (EFA_PTRS_PER_CHUNK) and has a 12-byte control buffer at the end of it holding the next chunk's pointer and its length. If the PBL number of pages is a multiple of EFA_PTRS_PER_CHUNK, the calculated last chunk length is wrongly computed as 0, even though that chunk is fully populated with 510 real page pointers. This wrong length is used both to DMA map the chunk and is propagated to the device, causing the device to see the chunk as empty and reject the memory registration. Fix the calculation so it will be performed only if the number of pages isn't a multiple of EFA_PTRS_PER_CHUNK, if it is, its already handled in the above loop correctly. Also prevent out-of-bounds reach in the chunks array in such scenario.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 40909f664d279765af430acc5db348a0b71c9b0a ~ 665cd418b8561a099c3854443f8ad8ae751b72a0 -
Linux Linux 5.2 -

II. Public POCs for CVE-2026-93264

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93264

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-93264 (8)

Same Patch Batch · Linux · 2026-09-24 · 234 CVEs total

CVE-2026-93207 9.8 CRITICAL SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
CVE-2026-97413 9.8 CRITICAL RDMA/rtrs-srv: Fix integer underflow in process_read and process_write
CVE-2026-93228 9.1 CRITICAL svcrdma: Reject Write/Reply chunks with segcount 0
CVE-2026-93793 8.8 HIGH wifi: iwlwifi: mvm: validate TX_CMD response layout
CVE-2026-93799 8.8 HIGH wifi: iwlwifi: mvm: validate sta_id in BA window status notif
CVE-2026-93790 8.8 HIGH wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif
CVE-2026-93806 8.8 HIGH wifi: cfg80211: validate assoc response length before status and IE access
CVE-2026-97442 8.8 HIGH wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi
CVE-2026-97509 8.8 HIGH thunderbolt: Keep XDomain reference during the lifetime of a service
CVE-2026-97409 8.8 HIGH nvme-fc: Do not cancel requests in io target before it is initialized
CVE-2026-93280 8.8 HIGH greybus: audio: bound the topology section sizes against the fetched size
CVE-2026-93284 8.8 HIGH drm/pagemap: dma-unmap pages before handling migration errors
CVE-2026-97451 8.4 HIGH ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op)
CVE-2026-97452 8.4 HIGH ACPICA: Prevent adding invalid references
CVE-2026-97455 8.4 HIGH ACPICA: Fix use-after-free in acpi_ds_terminate_control_method()
CVE-2026-97450 8.4 HIGH ACPICA: validate handler object type in two places
CVE-2026-93827 8.4 HIGH virtio-fs: avoid double-free on failed queue setup
CVE-2026-97433 8.2 HIGH nvme: validate FDP configuration descriptor sizes
CVE-2026-93221 8.1 HIGH nfsd: convert nfsd_net boolean flags to unsigned long flags word
CVE-2026-93786 8.1 HIGH ksmbd: preserve VFS inherited POSIX ACL mask

Showing top 20 of 234 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-93264

No comments yet


Leave a comment