Junglewise Threat Intelligence

CVE-2026-72465: Linux kernel xprtrdma credit grant validation bypass

CVE-2026-72465 · Severity: high · CVSS 7.5 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RDMA transport layer (used for remote procedure calls over RDMA networks) fails to validate credit grants from remote peers before processing them. An attacker on the network can send crafted replies with inflated credit values to exhaust memory and cause denial of service by forcing excessive allocation of receive buffers and work requests beyond configured limits.

Technical details

The vulnerability exists in the rpcrdma_reply_handler() function in net/sunrpc/xprtrdma/rpc_rdma.c. The credit value parsed from wire protocol is not validated before being used to allocate receive buffers; an out_norqst code path bypasses the credit clamping logic. A remote peer sending a well-formed RDMA reply with an unknown transaction ID (XID) and inflated credit grant can bypass bounds checking and cause rpcrdma_post_recvs() to allocate receive work requests past re_max_requests limits on each malicious reply. The fix moves credit sanitization (clamping to re_max_requests) immediately after parsing, before any branching that reaches buffer posting. Network-based attack vector; no authentication required beyond network connectivity.

Affected products

  • Linux Linux kernel multiple versions (patch applied to stable branches)

Timeline

  • 2026-08-15: disclosed
  • 2026-06-04: patched: upstream commit c3a628aab2dc8f5fd7bff86ceaeae64de590e60a by Chuck Lever
  • 2026-07-24: other: backported to stable kernels

References

Related threats