SB20260815257 - Improper input validation in Linux kernel sunrpc xprtrdma



SB20260815257 - Improper input validation in Linux kernel sunrpc xprtrdma

Published: August 15, 2026

Security Bulletin ID SB20260815257
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper input validation (CVE-ID: CVE-2026-72465)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in rpcrdma_reply_handler() and rpcrdma_post_recvs() when processing a well-formed reply with an unknown XID and an inflated credit grant. A remote attacker can send a specially crafted reply to cause a denial of service.

The issue occurs because the raw credit value parsed from the wire can reach Receive work request allocation logic without being clamped.


Remediation

Install update from vendor's website.