MANUALLYVERIFIEDREPORT package: kernel-6.19.11-200.fc43 ------ Summary: Heap out-of-bounds write in the Linux kernel RPC-over-RDMA server reply path (net/sunrpc/xprtrdma/svcrdmasendto.c). A crafted RPC-over-RDMA client can send a large NFS READ request with an empty Write list and no Reply chunk, causing the server to linearize the entire multi-page reply (up to 4 MB) into a fixed-size 4096-byte heap buffer (scxprtbuf) without bounds checking, resulting in a kernel heap overflow. This can crash the server (denial of service) or, with a carefully crafted payload, corrupt adjacent kernel heap objects for potential code execution. The vulnerable code path: 1. The buffer is allocated at 4096 bytes (svcrdmasendto.c, svcrdmasendctxtalloc()): c buffer = kmallocnode(rdma->scmaxreqsize, GFPKERNEL, node); / 4096 / xdrbufinit(&ctxt->schdrbuf, ctxt->scxprtbuf, rdma->scmaxreqsize); 2. With no Write chunk from the client, payload marking is skipped (svcrdmasendto.c, svcrdmaresultpayload()): c chunk = rctxt->rccurresultpayload; if (!length || !chunk) / chunk is NULL when Write list is empty / return 0; 3. So pclprocessnonpayloads() passes the entire reply to the actor (svcrdmapcl.c): c chunk = pclfirstchunk(pcl); if (!chunk || !chunk->chpayloadlength) return actor(xdr, data); / whole reply treated as non-payload / 4. The pull-up decision checks SGE count but never checks buffer capacity (svcrdmasendto.c, svcrdmapullupneeded()): c if (args.pdlength < RPCRDMAPULLUPTHRESH) return true; return args.pdnumsges >= rdma->scmaxsendsges; / no size-vs-buffer check / 5. The linearizer copies without bounds checking (svcrdmasendto.c, svcrdmaxblinearize()): c memcpy(args->pddest, xdr->head[0].iovbase, xdr->head[0].iovlen); / ... / memcpy(args->pddest, pageaddress(ppages) + pageoff, len); / OVERFLOW HERE / Requirements to exploit: The attacker needs network access to an NFS/RDMA service (InfiniBand or RoCE fabric) and valid NFS credentials (AUTHSYS or Kerberos) sufficient to issue a READ request against an exported file. AUTHSYS only requires being on an allowed IP/subnet with a valid UID claim. The NFS/RDMA server must be running with default configuration (sunrpc.svcrdma.maxreqsize=4096). The attacker must use a crafted RPC-over-RDMA client that omits Write and Reply chunks on a large READ request — stock Linux NFS clients do not produce this malformed pattern. No special privileges or user interaction are required beyond the initial NFS access. Component affected: kernel (net/sunrpc/xprtrdma/svcrdmasendto.c) Version affected: Needs further investigation. The vulnerable pull-up linearization path has been present since the pclprocessnonpayloads / svcrdmaxblinearize architecture was introduced. Likely affects all currently supported stable kernels with CONFIGSUNRPCXPRTRDMA + CONFIGNFSD enabled. Patch available: no Version fixed (if any already): N/A Upstream coordination: Not yet notified. Reporter submitted directly. Upstream notification should be coordinated via security. CVSS: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H — 8.8 (HIGH) Metric Value Rationale -------- ------- ----------- AV N NFS/RDMA listens on a network port; RoCEv2 deployments are IP-routable. AC L Default maxreqsize (4096) and scmaxsendsges (5) are the vulnerable values; no special conditions beyond a deployed NFS/RDMA service. PR L Requires valid NFS credentials (AUTHSYS or Kerberos) to issue a READ against an export. UI N No user interaction required. S U Impact confined to the kernel hosting the NFS/RDMA service. C H Kernel heap corruption can expose adjacent kernel memory contents. I H Heap out-of-bounds write can corrupt arbitrary adjacent kernel objects; potential for code execution. A H Reliable kernel crash/panic on overflow. Impact: Important. While the attacker requires low-privilege NFS credentials (AUTHSYS), the vulnerability escalates from constrained NFS file access to a kernel heap overflow on the server. This enables denial of service (reliable kernel crash) and potential arbitrary kernel code execution — a privilege boundary that AUTHSYS alone does not cross. The practical impact depends on deployment: NFS/RDMA requires RDMA hardware and explicit configuration, so exposure is limited to HPC, storage, and datacenter environments rather than general-purpose servers. Steps to reproduce if available: 1. Build a kernel with CONFIGSUNRPCXPRTRDMA, CONFIGNFSD, and CONFIGKASAN. Leave sunrpc.svcrdma.maxreqsize at the default (4096). 2. Start NFSd over RDMA on a device with standard default send-SGE budget. Export a readable file larger than 12288 bytes. 3. From a crafted RPC-over-RDMA client, send an NFSv3 READ request via rdmamsg with an empty Write list and no Reply chunk. Request at least 12288 bytes so the reply payload occupies three pages. 4. The server generates a multi-page reply. Because no Write chunk exists, svcrdmaresultpayload() is a no-op (rccurresultpayload is NULL). pclprocessnonpayloads() treats the full reply as non-payload. svcrdmapullupneeded() forces linearization because pdnumsges (5) matches scmaxsendsges (5). svcrdmaxblinearize() copies ~12 KB into the 4096-byte scxprtbuf. 5. With KASAN enabled, expect a heap out-of-bounds write report in svcrdmaxblinearize() / svcrdmapullupreplymsg() during the memcpy() sequence. ------ This report was generated using AI technology. Always review AI-generated content prior to use
Chromium: CVE-2025-12441 Out of bounds read in V8
Chromium: CVE-2025-12446 Incorrect security UI in SplitView
Chromium: CVE-2025-12433 Inappropriate implementation in V8
Chromium: CVE-2025-12445 Policy bypass in Extensions
Chromium: CVE-2025-12444 Incorrect security UI in Fullscreen UI
Chromium: CVE-2025-12728 Inappropriate implementation in Omnibox
Chromium: CVE-2025-12725 Out of bounds write in WebGPU
Chromium: CVE-2025-12727 Inappropriate implementation in V8
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Chromium: CVE-2025-14766 Use after free in WebGPU
Chromium: CVE-2025-11211 Out of bounds read in Media
Chromium: CVE-2025-11215 Off by one error in V8
Chromium: CVE-2025-11219 Use after free in V8
Chromium: CVE-2025-11460 Use after free in Storage
Chromium: CVE-2025-11458 Heap buffer overflow in Sync
Chromium: CVE-2025-11756 Use after free in Safe Browsing
Chromium: CVE-2025-12036 Inappropriate implementation in V8
Chromium: CVE-2025-12429 Inappropriate implementation in V8
Chromium: CVE-2025-12430 Object lifecycle issue in Media
Chromium: CVE-2025-12436 Policy bypass in Extensions
Chromium: CVE-2025-12433 Inappropriate implementation in V8
Chromium: CVE-2025-12432 Race in V8
Chromium: CVE-2025-12440 Inappropriate implementation in Autofill
Chromium: CVE-2025-12428 Type Confusion in V8
Chromium: CVE-2025-12438 Use after free in Ozone
Chromium: CVE-2025-12431 Inappropriate implementation in Extensions
Chromium: CVE-2025-12437 Use after free in PageInfo