Skip to main content
EPSS 0.7%top 49%

Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Sanitize the reply credit grant after parsing The out_norqst exit in… (CVE-2026-72465)

0
Medium
Published: 08/17/2026 (08/17/2026, 00:00:00 UTC)
Source: GCVE Database
Product: linux-hwe-edge

Description

In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Sanitize the reply credit grant after parsing The out_norqst exit in rpcrdma_reply_handler() branches away before the credit clamp, so a reply that matches no pending request reaches out_post carrying the raw credit value parsed from the wire. rpcrdma_post_recvs() does not bound its @needed argument: the refill loop allocates and chains Receive WRs until the count is satisfied or allocation fails. A peer that sends a well-formed reply carrying an unknown XID and an inflated credit grant therefore drives rep allocation and Receive posting past re_max_requests on every such reply. Move the clamp to immediately after the credit field is parsed, ahead of the first branch that can reach out_post, so every later consumer sees a sanitized value. The cwnd update stays on the matched-request path.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 16:21:31 UTC

Technical Analysis

The vulnerability in the Linux kernel's xprtrdma module involves improper sanitization of the reply credit grant in the rpcrdma_reply_handler() function. Specifically, the out_norqst exit path branches before the credit clamp is applied, allowing replies with unknown XIDs and inflated credit grants to reach out_post with raw credit values. Since rpcrdma_post_recvs() does not bound its 'needed' argument, a malicious peer can cause excessive allocation and chaining of Receive Work Requests beyond the re_max_requests limit. The patch moves the credit clamp immediately after parsing the credit field, ensuring all subsequent consumers handle a sanitized value, while keeping the congestion window update on the matched-request path.

Potential Impact

A remote peer can send well-formed replies with unknown transaction IDs and inflated credit grants to cause excessive resource allocation in the kernel's RDMA receive posting logic. This could lead to resource exhaustion or denial of service conditions by driving allocation and posting beyond intended limits.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability has been resolved in the Linux kernel by sanitizing the credit grant earlier in the processing flow. Users should monitor official Linux kernel advisories for patches addressing CVE-2026-72465 and apply them when available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-qhx3-pwwp-v2cp
Osv Schema Version
1.4.0
Aliases
["CVE-2026-72465"]

Threat ID: 6a808b6dbf8831d5394f8e53

Added to database: 08/15/2026, 15:53:17 UTC

Last enriched: 08/15/2026, 16:21:31 UTC

Last updated: 09/30/2026, 03:28:30 UTC

Views: 56

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses