๐Ÿ” CVE Alert

CVE-2026-72467

UNKNOWN 0.0

xprtrdma: Check frwr_wp_create() during connect

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Check frwr_wp_create() during connect frwr_wp_create() creates the singleton Memory Region used to encode padding for Write chunks whose payload length is not XDR-aligned. Its failure paths return a negative errno and leave ep->re_write_pad_mr set to NULL. rpcrdma_xprt_connect() currently ignores that return value. If frwr_wp_create() fails after the rest of the connection setup succeeds, xprt_rdma_connect_worker() treats the connection attempt as successful and sets XPRT_CONNECTED. A later NFS/RDMA read with a non-4-byte-aligned receive page length reaches rpcrdma_encode_write_list(), passes the NULL write-pad MR to encode_rdma_segment(), and dereferences it. This is locally triggerable on an NFS/RDMA client after a connect or reconnect hits a local MR allocation, DMA-map, MR-map, or post-send failure; a remote peer alone cannot force the local MR setup failure. Check the return value and fail the connect as -ENOTCONN, matching the adjacent setup failures. This keeps XPRT_CONNECTED clear and lets the normal reconnect path retry.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
21037b8c2258ec40de3b31be9ced43ceb3b784f7 < 3b252fe1778b2cdd68283146455929801bc2abd7 21037b8c2258ec40de3b31be9ced43ceb3b784f7 < dd798b76a3481e392820c3ae86ed4592858c6b0f 21037b8c2258ec40de3b31be9ced43ceb3b784f7 < 6b7be4f3feae322f1c2c40a3bdc99db93574a49e 21037b8c2258ec40de3b31be9ced43ceb3b784f7 < 7471e66373a4444a57ef2192f8c4081202c54f45 21037b8c2258ec40de3b31be9ced43ceb3b784f7 < ef3b79edf14b6bfb0d21a26ccb0463f9cf82c6a9 21037b8c2258ec40de3b31be9ced43ceb3b784f7 < 0f13fc7c7d2e0427517e63c739277a4cd338b0c5
Linux / Linux
5.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3b252fe1778b2cdd68283146455929801bc2abd7 git.kernel.org: https://git.kernel.org/stable/c/dd798b76a3481e392820c3ae86ed4592858c6b0f git.kernel.org: https://git.kernel.org/stable/c/6b7be4f3feae322f1c2c40a3bdc99db93574a49e git.kernel.org: https://git.kernel.org/stable/c/7471e66373a4444a57ef2192f8c4081202c54f45 git.kernel.org: https://git.kernel.org/stable/c/ef3b79edf14b6bfb0d21a26ccb0463f9cf82c6a9 git.kernel.org: https://git.kernel.org/stable/c/0f13fc7c7d2e0427517e63c739277a4cd338b0c5