Executive brief
The Linux kernel's SUNRPC (Sun Remote Procedure Call) network service implementation contains a buffer overflow vulnerability in its XDR data encoding function. An attacker can send specially crafted RPC requests that cause the kernel to write data past the end of an allocated array in kernel memory, potentially allowing arbitrary code execution or denial of service on systems providing NFS services.
Technical details
The xdr_buf_to_bvec() function in net/sunrpc/xdr.c writes bio_vec structures into a caller-supplied array without first checking whether the write location is within bounds. When the buffer allocation is exactly consumed, the next write lands one element past the end of the array (classic out-of-bounds write). The vulnerable code path includes head, page-loop, and tail branches, all performing stores before bounds checks. The rq_bvec array used by nfsd_vfs_write() is allocated to exactly rq_maxpages entries with no slack; the overflow can corrupt adjacent slab memory with bv_len and bv_offset fields derived from client-controlled RPC payload sizes. The fix moves bounds checks ahead of stores and changes the overflow return from count-1 to count, preventing the masking of the OOB write. This affects the NFS/SUNRPC subsystem and requires a kernel patch to remediate.
Affected products
- Linux Linux kernel 2.6.11 through 7.2 (all versions affected by vulnerability; patched in commits 42f5b80dda6b86e424054baf1475df686c403d5c and upstream backports)
Timeline
- 2026-08-15: disclosed
- 2026-06-09: patched: Upstream fix committed by Chuck Lever (commit 42f5b80dda6b86e424054baf1475df686c403d5c)