CVE-2026-72014: drbd: reject data replies with an out-of-range payload size
In the Linux kernel, the following vulnerability has been resolved:
drbd: reject data replies with an out-of-range payload size
recvdlessread() receives a PDATAREPLY from a peer into the bio of an outstanding read request. The peer-supplied payload length reaches it as the signed int datasize, and two peer-controlled inputs can make it negative. With a negotiated data-integrity-alg the digest length is subtracted first, so a reply whose payload is smaller than the digest underflows datasize. With no integrity algorithm (the default) datasize is assigned from the unsigned h95/h100 wire length and drbdd() never bounds it for a payload-carrying command, so a length above INTMAX casts it negative; this path needs no non-default feature. The bio receive loop then computes expect = mint(int, datasize, bvlen), which is negative, and drbdrecvallwarn(mapped, expect) receives with a sizet of SIZEMAX into the first mapped page.
The sibling receive path readinblock() is not affected: it uses an unsigned size and rejects it against DRBDMAXBIOSIZE before receiving. Reject a data reply whose size is negative after the optional digest subtraction, covering both triggers.
Impact: a malicious or man-in-the-middle DRBD peer copies attacker-chosen bytes past a bio page in the receiver, corrupting kernel memory. A node that reads from its peer (a diskless node, or read-balancing to the peer) is exposed in the default configuration; data-integrity-alg is not required.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
No special feature is required for the vulnerable path: the issue exists in the default configuration (no data-integrity-alg / default integrity behavior). Ensure the kernel fix (“Reject a data reply whose size is negative after the optional digest”) is applied for DRBD P_DATA_REPLY handling.
DRBD data-integrity-alg = not required (default path remains affected per description)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72014?
The severity of CVE-2026-72014 is rated at 80.
What types of systems are affected by CVE-2026-72014?
CVE-2026-72014 affects systems running the Linux kernel utilizing DRBD.
How do I fix CVE-2026-72014?
To fix CVE-2026-72014, upgrade to the patched version of the Linux kernel that addresses this vulnerability.
What is the main issue described in CVE-2026-72014?
CVE-2026-72014 describes a vulnerability where data replies with out-of-range payload sizes can be incorrectly processed.
Is CVE-2026-72014 an easy vulnerability to exploit?
CVE-2026-72014 may require specific conditions and knowledge of the system to exploit effectively.