-

CVE-2026-72467

xprtrdma: Check frwr_wp_create() during connect

In the Linux kernel, the following vulnerability has been resolved:

xprtrdma: Check frwr_wp_create() during connect

frwr_wp_create() creates the singleton Memory Region used to encode
padding for Write chunks whose payload length is not XDR-aligned. Its
failure paths return a negative errno and leave ep->re_write_pad_mr set
to NULL.

rpcrdma_xprt_connect() currently ignores that return value. If
frwr_wp_create() fails after the rest of the connection setup succeeds,
xprt_rdma_connect_worker() treats the connection attempt as successful
and sets XPRT_CONNECTED. A later NFS/RDMA read with a non-4-byte-aligned
receive page length reaches rpcrdma_encode_write_list(), passes the NULL
write-pad MR to encode_rdma_segment(), and dereferences it.

This is locally triggerable on an NFS/RDMA client after a connect or
reconnect hits a local MR allocation, DMA-map, MR-map, or post-send
failure; a remote peer alone cannot force the local MR setup failure.

Check the return value and fail the connect as -ENOTCONN, matching the
adjacent setup failures. This keeps XPRT_CONNECTED clear and lets the
normal reconnect path retry.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 21037b8c2258ec40de3b31be9ced43ceb3b784f7
Version < 3b252fe1778b2cdd68283146455929801bc2abd7
Status affected
Version 21037b8c2258ec40de3b31be9ced43ceb3b784f7
Version < dd798b76a3481e392820c3ae86ed4592858c6b0f
Status affected
Version 21037b8c2258ec40de3b31be9ced43ceb3b784f7
Version < 6b7be4f3feae322f1c2c40a3bdc99db93574a49e
Status affected
Version 21037b8c2258ec40de3b31be9ced43ceb3b784f7
Version < 7471e66373a4444a57ef2192f8c4081202c54f45
Status affected
Version 21037b8c2258ec40de3b31be9ced43ceb3b784f7
Version < ef3b79edf14b6bfb0d21a26ccb0463f9cf82c6a9
Status affected
Version 21037b8c2258ec40de3b31be9ced43ceb3b784f7
Version < 0f13fc7c7d2e0427517e63c739277a4cd338b0c5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.16
Status affected
Version 0
Version < 5.16
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.109
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3b252fe1778b2cdd68283146455929801bc2abd7
https://git.kernel.org/stable/c/dd798b76a3481e392820c3ae86ed4592858c6b0f
https://git.kernel.org/stable/c/6b7be4f3feae322f1c2c40a3bdc99db93574a49e
https://git.kernel.org/stable/c/7471e66373a4444a57ef2192f8c4081202c54f45
https://git.kernel.org/stable/c/ef3b79edf14b6bfb0d21a26ccb0463f9cf82c6a9
https://git.kernel.org/stable/c/0f13fc7c7d2e0427517e63c739277a4cd338b0c5