In the Linux kernel, the following vulnerability has been resolved: svcrdma: bound check rq_pages index in inline path svc_rdma_copy_inline_range indexed rqstp->rq_pages[rc_curpage] without verifying rc_curpage stays within the allocated page array. Add guards before the first use and after advancing to a new page.
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | 1.0 |
| Linux | Linux | < 10.0.26100.2314 |
| Linux | Linux | < 10.0.10240.20826 |