{"id":"CVE-2026-13087","published":"2026-09-22T17:17:23.807","lastModified":"2026-09-22T19:37:36.747","description":"A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large NFS READ request with an empty Write list and no Reply chunk, the server linearizes the entire multi-page reply into a fixed-size 4096-byte heap buffer without bounds checking, resulting in a kernel heap overflow. This can lead to denial of service via kernel crash or potential code execution through corruption of adjacent kernel heap objects.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-787"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-13087","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2470788","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2470788","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw involves a heap out-of-bounds write vulnerability in the Linux kernel's RPC-over-RDMA server, which can lead to a kernel heap overflow and potential code execution.","exploitability":"Exploitation requires a crafted RPC-over-RDMA client sending a specific type of request, making it moderately difficult. The client must be able to send a large NFS READ request with an empty Write list and no Reply chunk.","blast_radius":"If exploited, this vulnerability could result in a denial of service via a kernel crash or potential code execution, impacting the stability and security of the system.","remediation":"Upgrade to the latest stable kernel version, as a specific patch is available to address this issue.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","heap-overflow","rdma","kernel","nfs"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:55:11.214Z"}}