SB20260816312 - Out-of-bounds write in Linux kernel sunrpc
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-72217)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in xdr_buf_to_bvec() when processing client-supplied RPC payload sizes. A remote attacker can send a specially crafted RPC request to cause memory corruption.
The out-of-bounds store can write one element past the end of the bio_vec array into adjacent slab memory, and the written length and offset fields are derived from client-controlled payload sizes.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/42f5b80dda6b86e424054baf1475df686c403d5c
- https://git.kernel.org/stable/c/4a1148f2739d5089c3ca8ae2e9d1053e219ab5df
- https://git.kernel.org/stable/c/6029e711a818bf34d6c4b90cafee24f3afffa110
- https://git.kernel.org/stable/c/69e18135e2a004a79505451dbef07314ea16e1eb
- https://git.kernel.org/stable/c/98414b42530af65cb984ffc12685096a3b5e179a