← Back to search

CVE-2026-13087

8.8 HIGH

Published 2026-09-22 · Updated 2026-09-22

AI risk analysis

Summary
The flaw involves a heap out-of-bounds write vulnerability in the Linux kernel's RPC-over-RDMA server, which can lead to a kernel heap overflow and potential code execution.
Exploitability
Exploitation requires a crafted RPC-over-RDMA client sending a specific type of request, making it moderately difficult. The client must be able to send a large NFS READ request with an empty Write list and no Reply chunk.
Blast radius
If exploited, this vulnerability could result in a denial of service via a kernel crash or potential code execution, impacting the stability and security of the system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest stable kernel version, as a specific patch is available to address this issue.
rceheap-overflowrdmakernelnfs

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large NFS READ request with an empty Write list and no Reply chunk, the server linearizes the entire multi-page reply into a fixed-size 4096-byte heap buffer without bounds checking, resulting in a kernel heap overflow. This can lead to denial of service via kernel crash or potential code execution through corruption of adjacent kernel heap objects.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-787

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.