CVE-2026-13087
8.8 HIGHPublished 2026-09-22 · Updated 2026-09-22
AI risk analysis
- Summary
- The flaw involves a heap out-of-bounds write vulnerability in the Linux kernel's RPC-over-RDMA server, which can lead to a kernel heap overflow and potential code execution.
- Exploitability
- Exploitation requires a crafted RPC-over-RDMA client sending a specific type of request, making it moderately difficult. The client must be able to send a large NFS READ request with an empty Write list and no Reply chunk.
- Blast radius
- If exploited, this vulnerability could result in a denial of service via a kernel crash or potential code execution, impacting the stability and security of the system.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the latest stable kernel version, as a specific patch is available to address this issue.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large NFS READ request with an empty Write list and no Reply chunk, the server linearizes the entire multi-page reply into a fixed-size 4096-byte heap buffer without bounds checking, resulting in a kernel heap overflow. This can lead to denial of service via kernel crash or potential code execution through corruption of adjacent kernel heap objects.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-787
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-17052PoC
- CRITICALCVE-2017-20241
- CRITICALCVE-2026-100075
- CRITICALCVE-2026-10747
- HIGHCVE-2026-64582
- CRITICALCVE-2026-89847
- CRITICALCVE-2026-90036
- CRITICALCVE-2026-90037
Related by shared AI tags and CWE weakness class. Browse the full archive.