Improper input validation in Linux kernel - CVE-2026-72465
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in rpcrdma_reply_handler() and rpcrdma_post_recvs() when processing a well-formed reply with an unknown XID and an inflated credit grant. A remote attacker can send a specially crafted reply to cause a denial of service.
The issue occurs because the raw credit value parsed from the wire can reach Receive work request allocation logic without being clamped.
Affected software
How to mitigate CVE-2026-72465
External References
- https://git.kernel.org/stable/c/33db78b1b24fc6a464ae08aa4d2538c5f883eb5e
- https://git.kernel.org/stable/c/41634242140173eabbf54f899f9c70b5c685e786
- https://git.kernel.org/stable/c/469b22376ee73369711ecf2761bd122ef4195963
- https://git.kernel.org/stable/c/7cf332b3d82d73ffceedca6b4a120be074172021
- https://git.kernel.org/stable/c/8be1bb378def94a5cb8f7527a191e476407118ec
- https://git.kernel.org/stable/c/c3a628aab2dc8f5fd7bff86ceaeae64de590e60a