Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Sanitize the reply credit grant after parsing The out_norqst exit in… (CVE-2026-72465)
In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Sanitize the reply credit grant after parsing The out_norqst exit in rpcrdma_reply_handler() branches away before the credit clamp, so a reply that matches no pending request reaches out_post carrying the raw credit value parsed from the wire. rpcrdma_post_recvs() does not bound its @needed argument: the refill loop allocates and chains Receive WRs until the count is satisfied or allocation fails. A peer that sends a well-formed reply carrying an unknown XID and an inflated credit grant therefore drives rep allocation and Receive posting past re_max_requests on every such reply. Move the clamp to immediately after the credit field is parsed, ahead of the first branch that can reach out_post, so every later consumer sees a sanitized value. The cwnd update stays on the matched-request path.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel's xprtrdma module involves improper sanitization of the reply credit grant in the rpcrdma_reply_handler() function. Specifically, the out_norqst exit path branches before the credit clamp is applied, allowing replies with unknown XIDs and inflated credit grants to reach out_post with raw credit values. Since rpcrdma_post_recvs() does not bound its 'needed' argument, a malicious peer can cause excessive allocation and chaining of Receive Work Requests beyond the re_max_requests limit. The patch moves the credit clamp immediately after parsing the credit field, ensuring all subsequent consumers handle a sanitized value, while keeping the congestion window update on the matched-request path.
Potential Impact
A remote peer can send well-formed replies with unknown transaction IDs and inflated credit grants to cause excessive resource allocation in the kernel's RDMA receive posting logic. This could lead to resource exhaustion or denial of service conditions by driving allocation and posting beyond intended limits.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability has been resolved in the Linux kernel by sanitizing the credit grant earlier in the processing flow. Users should monitor official Linux kernel advisories for patches addressing CVE-2026-72465 and apply them when available.
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Sanitize the reply credit grant after parsing The out_norqst exit in… (CVE-2026-72465)
Description
In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Sanitize the reply credit grant after parsing The out_norqst exit in rpcrdma_reply_handler() branches away before the credit clamp, so a reply that matches no pending request reaches out_post carrying the raw credit value parsed from the wire. rpcrdma_post_recvs() does not bound its @needed argument: the refill loop allocates and chains Receive WRs until the count is satisfied or allocation fails. A peer that sends a well-formed reply carrying an unknown XID and an inflated credit grant therefore drives rep allocation and Receive posting past re_max_requests on every such reply. Move the clamp to immediately after the credit field is parsed, ahead of the first branch that can reach out_post, so every later consumer sees a sanitized value. The cwnd update stays on the matched-request path.
CVSS v3.1
Score 7.5high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel's xprtrdma module involves improper sanitization of the reply credit grant in the rpcrdma_reply_handler() function. Specifically, the out_norqst exit path branches before the credit clamp is applied, allowing replies with unknown XIDs and inflated credit grants to reach out_post with raw credit values. Since rpcrdma_post_recvs() does not bound its 'needed' argument, a malicious peer can cause excessive allocation and chaining of Receive Work Requests beyond the re_max_requests limit. The patch moves the credit clamp immediately after parsing the credit field, ensuring all subsequent consumers handle a sanitized value, while keeping the congestion window update on the matched-request path.
Potential Impact
A remote peer can send well-formed replies with unknown transaction IDs and inflated credit grants to cause excessive resource allocation in the kernel's RDMA receive posting logic. This could lead to resource exhaustion or denial of service conditions by driving allocation and posting beyond intended limits.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability has been resolved in the Linux kernel by sanitizing the credit grant earlier in the processing flow. Users should monitor official Linux kernel advisories for patches addressing CVE-2026-72465 and apply them when available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-qhx3-pwwp-v2cp
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-72465"]
Threat ID: 6a808b6dbf8831d5394f8e53
Added to database: 08/15/2026, 15:53:17 UTC
Last enriched: 08/15/2026, 16:21:31 UTC
Last updated: 09/30/2026, 03:28:30 UTC
Views: 56
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.