{"id":"CVE-2026-72465","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-72465","summary":"xprtrdma: Sanitize the reply credit grant after parsing","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Sanitize the reply credit grant after parsing\n\nThe out_norqst exit in rpcrdma_reply_handler() branches away before\nthe credit clamp, so a reply that matches no pending request reaches\nout_post carrying the raw credit value parsed from the wire.\nrpcrdma_post_recvs() does not bound its @needed argument: the refill\nloop allocates and chains Receive WRs until the count is satisfied or\nallocation fails. A peer that sends a well-formed reply carrying an\nunknown XID and an inflated credit grant therefore drives rep\nallocation and Receive posting past re_max_requests on every such\nreply.\n\nMove the clamp to immediately after the credit field is parsed,\nahead of the first branch that can reach out_post, so every later\nconsumer sees a sanitized value. The cwnd update stays on the\nmatched-request path.","published":"2026-08-15T05:57:08.767Z","modified":"2026-08-18T03:56:26.383905771Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"7.1.5"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/33db78b1b24fc6a464ae08aa4d2538c5f883eb5e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/41634242140173eabbf54f899f9c70b5c685e786"},{"type":"WEB","url":"https://git.kernel.org/stable/c/469b22376ee73369711ecf2761bd122ef4195963"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7cf332b3d82d73ffceedca6b4a120be074172021"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8be1bb378def94a5cb8f7527a191e476407118ec"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c3a628aab2dc8f5fd7bff86ceaeae64de590e60a"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72465.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72465"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T03:56:26.383905771Z"}}