CVE-2026-13087: Kernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path...

Published May 11, 2026
·
Updated

MANUALLYVERIFIEDREPORT package: kernel-6.19.11-200.fc43 ------ Summary: Heap out-of-bounds write in the Linux kernel RPC-over-RDMA server reply path (net/sunrpc/xprtrdma/svcrdmasendto.c). A crafted RPC-over-RDMA client can send a large NFS READ request with an empty Write list and no Reply chunk, causing the server to linearize the entire multi-page reply (up to 4 MB) into a fixed-size 4096-byte heap buffer (scxprtbuf) without bounds checking, resulting in a kernel heap overflow. This can crash the server (denial of service) or, with a carefully crafted payload, corrupt adjacent kernel heap objects for potential code execution. The vulnerable code path: 1. The buffer is allocated at 4096 bytes (svcrdmasendto.c, svcrdmasendctxtalloc()): c buffer = kmallocnode(rdma->scmaxreqsize, GFPKERNEL, node); / 4096 / xdrbufinit(&ctxt->schdrbuf, ctxt->scxprtbuf, rdma->scmaxreqsize); 2. With no Write chunk from the client, payload marking is skipped (svcrdmasendto.c, svcrdmaresultpayload()): c chunk = rctxt->rccurresultpayload; if (!length || !chunk) / chunk is NULL when Write list is empty / return 0; 3. So pclprocessnonpayloads() passes the entire reply to the actor (svcrdmapcl.c): c chunk = pclfirstchunk(pcl); if (!chunk || !chunk->chpayloadlength) return actor(xdr, data); / whole reply treated as non-payload / 4. The pull-up decision checks SGE count but never checks buffer capacity (svcrdmasendto.c, svcrdmapullupneeded()): c if (args.pdlength < RPCRDMAPULLUPTHRESH) return true; return args.pdnumsges >= rdma->scmaxsendsges; / no size-vs-buffer check / 5. The linearizer copies without bounds checking (svcrdmasendto.c, svcrdmaxblinearize()): c memcpy(args->pddest, xdr->head[0].iovbase, xdr->head[0].iovlen); / ... / memcpy(args->pddest, pageaddress(ppages) + pageoff, len); / OVERFLOW HERE / Requirements to exploit: The attacker needs network access to an NFS/RDMA service (InfiniBand or RoCE fabric) and valid NFS credentials (AUTHSYS or Kerberos) sufficient to issue a READ request against an exported file. AUTHSYS only requires being on an allowed IP/subnet with a valid UID claim. The NFS/RDMA server must be running with default configuration (sunrpc.svcrdma.maxreqsize=4096). The attacker must use a crafted RPC-over-RDMA client that omits Write and Reply chunks on a large READ request — stock Linux NFS clients do not produce this malformed pattern. No special privileges or user interaction are required beyond the initial NFS access. Component affected: kernel (net/sunrpc/xprtrdma/svcrdmasendto.c) Version affected: Needs further investigation. The vulnerable pull-up linearization path has been present since the pclprocessnonpayloads / svcrdmaxblinearize architecture was introduced. Likely affects all currently supported stable kernels with CONFIGSUNRPCXPRTRDMA + CONFIGNFSD enabled. Patch available: no Version fixed (if any already): N/A Upstream coordination: Not yet notified. Reporter submitted directly. Upstream notification should be coordinated via security. CVSS: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H — 8.8 (HIGH) Metric Value Rationale -------- ------- ----------- AV N NFS/RDMA listens on a network port; RoCEv2 deployments are IP-routable. AC L Default maxreqsize (4096) and scmaxsendsges (5) are the vulnerable values; no special conditions beyond a deployed NFS/RDMA service. PR L Requires valid NFS credentials (AUTHSYS or Kerberos) to issue a READ against an export. UI N No user interaction required. S U Impact confined to the kernel hosting the NFS/RDMA service. C H Kernel heap corruption can expose adjacent kernel memory contents. I H Heap out-of-bounds write can corrupt arbitrary adjacent kernel objects; potential for code execution. A H Reliable kernel crash/panic on overflow. Impact: Important. While the attacker requires low-privilege NFS credentials (AUTHSYS), the vulnerability escalates from constrained NFS file access to a kernel heap overflow on the server. This enables denial of service (reliable kernel crash) and potential arbitrary kernel code execution — a privilege boundary that AUTHSYS alone does not cross. The practical impact depends on deployment: NFS/RDMA requires RDMA hardware and explicit configuration, so exposure is limited to HPC, storage, and datacenter environments rather than general-purpose servers. Steps to reproduce if available: 1. Build a kernel with CONFIGSUNRPCXPRTRDMA, CONFIGNFSD, and CONFIGKASAN. Leave sunrpc.svcrdma.maxreqsize at the default (4096). 2. Start NFSd over RDMA on a device with standard default send-SGE budget. Export a readable file larger than 12288 bytes. 3. From a crafted RPC-over-RDMA client, send an NFSv3 READ request via rdmamsg with an empty Write list and no Reply chunk. Request at least 12288 bytes so the reply payload occupies three pages. 4. The server generates a multi-page reply. Because no Write chunk exists, svcrdmaresultpayload() is a no-op (rccurresultpayload is NULL). pclprocessnonpayloads() treats the full reply as non-payload. svcrdmapullupneeded() forces linearization because pdnumsges (5) matches scmaxsendsges (5). svcrdmaxblinearize() copies ~12 KB into the 4096-byte scxprtbuf. 5. With KASAN enabled, expect a heap out-of-bounds write report in svcrdmaxblinearize() / svcrdmapullupreplymsg() during the memcpy() sequence. ------ This report was generated using AI technology. Always review AI-generated content prior to use

Other sources

Rejected reason: This CVE was reserved in error and duplicates CVE-2026-89530.

— NVD

Affected Software

1 affected component
Linux Linux kernel

Event History

May 11, 2026
Data Sourced
via Red Hat·08:52 PM
DescriptionSeverityAffected Software
Sep 22, 2026
CVE Published
via MITRE·04:51 PM
Rejected
via MITRE·04:51 PM
Data Sourced
via NVD·05:17 PM
Description
Sep 30, 2026
Rejected
via MITRE·04:22 PM

Frequently Asked Questions

1

Which deployments are exposed?

Systems acting as an RPC-over-RDMA server and handling NFS READ requests are exposed to the vulnerable reply path. The affected code is in the Linux kernel RPC-over-RDMA server implementation.

2

What does an attacker need to trigger the issue?

An attacker needs network access to the RPC-over-RDMA service and low privileges. They must send a crafted large NFS READ request with an empty Write list and no Reply chunk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203