Where
-Infinity
0
Severity
7

MANUALLYVERIFIEDREPORT package: kernel-6.19.11-200.fc43 ------ Summary: Heap out-of-bounds write in the Linux kernel RPC-over-RDMA server reply path (net/sunrpc/xprtrdma/svcrdmasendto.c). A crafted RPC-over-RDMA client can send a large NFS READ request with an empty Write list and no Reply chunk, causing the server to linearize the entire multi-page reply (up to 4 MB) into a fixed-size 4096-byte heap buffer (scxprtbuf) without bounds checking, resulting in a kernel heap overflow. This can crash the server (denial of service) or, with a carefully crafted payload, corrupt adjacent kernel heap objects for potential code execution. The vulnerable code path: 1. The buffer is allocated at 4096 bytes (svcrdmasendto.c, svcrdmasendctxtalloc()): c buffer = kmallocnode(rdma->scmaxreqsize, GFPKERNEL, node); / 4096 / xdrbufinit(&ctxt->schdrbuf, ctxt->scxprtbuf, rdma->scmaxreqsize); 2. With no Write chunk from the client, payload marking is skipped (svcrdmasendto.c, svcrdmaresultpayload()): c chunk = rctxt->rccurresultpayload; if (!length || !chunk) / chunk is NULL when Write list is empty / return 0; 3. So pclprocessnonpayloads() passes the entire reply to the actor (svcrdmapcl.c): c chunk = pclfirstchunk(pcl); if (!chunk || !chunk->chpayloadlength) return actor(xdr, data); / whole reply treated as non-payload / 4. The pull-up decision checks SGE count but never checks buffer capacity (svcrdmasendto.c, svcrdmapullupneeded()): c if (args.pdlength < RPCRDMAPULLUPTHRESH) return true; return args.pdnumsges >= rdma->scmaxsendsges; / no size-vs-buffer check / 5. The linearizer copies without bounds checking (svcrdmasendto.c, svcrdmaxblinearize()): c memcpy(args->pddest, xdr->head[0].iovbase, xdr->head[0].iovlen); / ... / memcpy(args->pddest, pageaddress(ppages) + pageoff, len); / OVERFLOW HERE / Requirements to exploit: The attacker needs network access to an NFS/RDMA service (InfiniBand or RoCE fabric) and valid NFS credentials (AUTHSYS or Kerberos) sufficient to issue a READ request against an exported file. AUTHSYS only requires being on an allowed IP/subnet with a valid UID claim. The NFS/RDMA server must be running with default configuration (sunrpc.svcrdma.maxreqsize=4096). The attacker must use a crafted RPC-over-RDMA client that omits Write and Reply chunks on a large READ request — stock Linux NFS clients do not produce this malformed pattern. No special privileges or user interaction are required beyond the initial NFS access. Component affected: kernel (net/sunrpc/xprtrdma/svcrdmasendto.c) Version affected: Needs further investigation. The vulnerable pull-up linearization path has been present since the pclprocessnonpayloads / svcrdmaxblinearize architecture was introduced. Likely affects all currently supported stable kernels with CONFIGSUNRPCXPRTRDMA + CONFIGNFSD enabled. Patch available: no Version fixed (if any already): N/A Upstream coordination: Not yet notified. Reporter submitted directly. Upstream notification should be coordinated via security. CVSS: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H — 8.8 (HIGH) Metric Value Rationale -------- ------- ----------- AV N NFS/RDMA listens on a network port; RoCEv2 deployments are IP-routable. AC L Default maxreqsize (4096) and scmaxsendsges (5) are the vulnerable values; no special conditions beyond a deployed NFS/RDMA service. PR L Requires valid NFS credentials (AUTHSYS or Kerberos) to issue a READ against an export. UI N No user interaction required. S U Impact confined to the kernel hosting the NFS/RDMA service. C H Kernel heap corruption can expose adjacent kernel memory contents. I H Heap out-of-bounds write can corrupt arbitrary adjacent kernel objects; potential for code execution. A H Reliable kernel crash/panic on overflow. Impact: Important. While the attacker requires low-privilege NFS credentials (AUTHSYS), the vulnerability escalates from constrained NFS file access to a kernel heap overflow on the server. This enables denial of service (reliable kernel crash) and potential arbitrary kernel code execution — a privilege boundary that AUTHSYS alone does not cross. The practical impact depends on deployment: NFS/RDMA requires RDMA hardware and explicit configuration, so exposure is limited to HPC, storage, and datacenter environments rather than general-purpose servers. Steps to reproduce if available: 1. Build a kernel with CONFIGSUNRPCXPRTRDMA, CONFIGNFSD, and CONFIGKASAN. Leave sunrpc.svcrdma.maxreqsize at the default (4096). 2. Start NFSd over RDMA on a device with standard default send-SGE budget. Export a readable file larger than 12288 bytes. 3. From a crafted RPC-over-RDMA client, send an NFSv3 READ request via rdmamsg with an empty Write list and no Reply chunk. Request at least 12288 bytes so the reply payload occupies three pages. 4. The server generates a multi-page reply. Because no Write chunk exists, svcrdmaresultpayload() is a no-op (rccurresultpayload is NULL). pclprocessnonpayloads() treats the full reply as non-payload. svcrdmapullupneeded() forces linearization because pdnumsges (5) matches scmaxsendsges (5). svcrdmaxblinearize() copies ~12 KB into the 4096-byte scxprtbuf. 5. With KASAN enabled, expect a heap out-of-bounds write report in svcrdmaxblinearize() / svcrdmapullupreplymsg() during the memcpy() sequence. ------ This report was generated using AI technology. Always review AI-generated content prior to use

1 / 2
Source: Red Hat
First published (updated )
Severity
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Chromium: CVE-2025-12441 Out of bounds read in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
4.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L

Chromium: CVE-2025-12446 Incorrect security UI in SplitView

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Chromium: CVE-2025-12433 Inappropriate implementation in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Chromium: CVE-2025-12445 Policy bypass in Extensions

1 / 3
Source: Microsoft
First published (updated )
Severity
4.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L

Chromium: CVE-2025-12444 Incorrect security UI in Fullscreen UI

1 / 3
Source: Microsoft
First published (updated )
Severity
4.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L

Chromium: CVE-2025-12728 Inappropriate implementation in Omnibox

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-12725 Out of bounds write in WebGPU

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-12727 Inappropriate implementation in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
5.4
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

First published (updated )
Severity
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

First published (updated )
Severity
4.3
EPSS
0.08%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-14766 Use after free in WebGPU

1 / 3
Source: Microsoft
First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Chromium: CVE-2025-11211 Out of bounds read in Media

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Chromium: CVE-2025-11215 Off by one error in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
3.1
Use After Free
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Chromium: CVE-2025-11219 Use after free in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-11460 Use after free in Storage

1 / 3
Source: Microsoft
First published (updated )
Severity
8.1
Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Chromium: CVE-2025-11458 Heap buffer overflow in Sync

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-11756 Use after free in Safe Browsing

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-12036 Inappropriate implementation in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-12429 Inappropriate implementation in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Chromium: CVE-2025-12430 Object lifecycle issue in Media

1 / 3
Source: Microsoft
First published (updated )
Severity
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Chromium: CVE-2025-12436 Policy bypass in Extensions

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Chromium: CVE-2025-12433 Inappropriate implementation in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
Race Condition
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-12432 Race in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
5.3
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Chromium: CVE-2025-12440 Inappropriate implementation in Autofill

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-12428 Type Confusion in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-12438 Use after free in Ozone

1 / 3
Source: Microsoft
First published (updated )
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Chromium: CVE-2025-12431 Inappropriate implementation in Extensions

1 / 3
Source: Microsoft
First published (updated )
Severity
7.5
Use After Free
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-12437 Use after free in PageInfo

1 / 3
Source: Microsoft
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203