{"apiVersion":"1.0","identifier":"CVE-2026-72464","description":"In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Repost Receive buffers for malformed replies rpcrdma_wc_receive() decrements the transport-s Receive count for every completion before it dispatches a successful Receive to rpcrdma_reply_handler(). The handler must post a replacement Receive WR before returning unless ownership of the rep has moved elsewhere, as on the backchannel path. Commit 2ae50ad68cd7 (-xprtrdma: Close window between waking RPC senders and posting Receives-) moved the Receive refill out of rpcrdma_wc_receive(), where it had run ahead of every reply, into rpcrdma_reply_handler() so that the responder-s credit grant could be parsed before reposting. The bad-version and short-reply exits never reach that refill: they recycle the rep and return without calling rpcrdma_post_recvs(). A remote peer can therefore drain the client-s posted Receive queue by sending a sustained stream of replies that are shorter than the fixed transport header or that carry an unrecognized RPC/RDMA version. Each such reply consumes one posted Receive without replacing it. Once the queue empties, the peer-s next Send finds no posted Receive and the transport stalls until reconnect. Route both malformed-reply exits through the shared repost tail after recycling the rep, refilling against buf->rb_credits, the most recent accepted credit grant. Neither exit updates the congestion window, so RPCs admitted under the previous grant remain in flight awaiting replies. A smaller refill target would let a stream of malformed replies ratchet the posted Receive count down to the batch floor while the congestion window still admits rb_credits RPCs; a burst of valid replies to those RPCs could then overrun the posted Receives, and because the client connects with rnr_retry_count of zero, a single RNR NAK terminates the connection. Refilling against rb_credits also restores the target that applied to malformed replies before commit 2ae50ad68cd7 (-xprtrdma: Close window between waking RPC senders and posting Receives-) when rpcrdma_post_recvs() computed it from rb_credits internally. rb_credits is at least one from connection establishment onward, so the repost path always keeps Receives posted.","publishedAt":"2026-08-15T06:22:20","lastModifiedAt":"2026-08-17T06:19:14","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72464","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","epssProbability":0.00675,"riskScore":0.8,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72464","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72464","en":"https://www.redsauce.net/en/cves/CVE-2026-72464","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72464","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72464","de":"https://www.redsauce.net/de/cves/CVE-2026-72464","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72464","el":"https://www.redsauce.net/el/cves/CVE-2026-72464"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72464"}}