In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Read lists that exceed the page budget Individual Read segment lengths are validated at decode time, but nothing prevents a requester from sending multiple segments whose cumulative length exceeds the rq_pages array budget. When one segment fills the page array exactly, the runtime guard in svc_rdma_build_read_segment() is bypassed because len reaches zero. A subsequent segment then accesses the NULL sentinel slot at rq_pages[rq_maxpages], resulting in a NULL pointer dereference during DMA mapping. Accumulate pages across all Read segments and reject the message at decode time when the total would overflow the page budget.
https://git.kernel.org/stable/c/465f511f59a0fa7a80d5d1073c4b24f28ea38f58
https://git.kernel.org/stable/c/1a3af2262cb384112ef38632de4690682be528b4
https://git.kernel.org/stable/c/0ca487abb3bdf581851664b5db21f364caf57682