« Volver al listado

CVE-2026-72468

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

xprtrdma: Initialize re_id before removal registration

rpcrdma_create_id() registers ep->re_rn with the rpcrdma ib_client before returning the new rdma_cm_id to rpcrdma_ep_create(). However rpcrdma_ep_create() currently stores that pointer in ep->re_id only after rpcrdma_create_id() returns.

A local administrator can race an NFS/RDMA mount against RDMA device removal. If rpcrdma_remove_one() observes the just-registered notification before rpcrdma_ep_create() assigns ep->re_id, rpcrdma_ep_removal_done() calls trace_xprtrdma_device_removal(NULL). The tracepoint dereferences id->device->name and copies id->route.addr.dst_addr, so the callback can crash the kernel with a NULL pointer dereference.

Leer descripción completaMostrar menos

Store the rdma_cm_id in ep->re_id immediately before publishing ep->re_rn. The existing error path still destroys the id directly if registration fails; ep is then freed by the caller without using ep->re_id. Remove the later duplicate assignment in rpcrdma_ep_create().

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72468",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3f4eb9ff923413cdb4c7e171c06d3564f6286712",
              "lessThan": "51248d877bbc6e604e38aeaf776c2781cb4f0dbd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3f4eb9ff923413cdb4c7e171c06d3564f6286712",
              "lessThan": "28743571c17b58c21a7216fc9faaf8028df5869b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3f4eb9ff923413cdb4c7e171c06d3564f6286712",
              "lessThan": "264ccd7871915749bee55fe0c39467a7f08d5479",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3f4eb9ff923413cdb4c7e171c06d3564f6286712",
              "lessThan": "bb7caa63e1db22fd03e8dc591b12169e99169dff",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/sunrpc/xprtrdma/verbs.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/sunrpc/xprtrdma/verbs.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:20.877",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/264ccd7871915749bee55fe0c39467a7f08d5479",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/28743571c17b58c21a7216fc9faaf8028df5869b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/51248d877bbc6e604e38aeaf776c2781cb4f0dbd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bb7caa63e1db22fd03e8dc591b12169e99169dff",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Initialize re_id before removal registration\n\nrpcrdma_create_id() registers ep->re_rn with the rpcrdma ib_client\nbefore returning the new rdma_cm_id to rpcrdma_ep_create(). However\nrpcrdma_ep_create() currently stores that pointer in ep->re_id only\nafter rpcrdma_create_id() returns.\n\nA local administrator can race an NFS/RDMA mount against RDMA device\nremoval. If rpcrdma_remove_one() observes the just-registered\nnotification before rpcrdma_ep_create() assigns ep->re_id,\nrpcrdma_ep_removal_done() calls trace_xprtrdma_device_removal(NULL).\nThe tracepoint dereferences id->device->name and copies\nid->route.addr.dst_addr, so the callback can crash the kernel with a\nNULL pointer dereference.\n\nStore the rdma_cm_id in ep->re_id immediately before publishing\nep->re_rn. The existing error path still destroys the id directly if\nregistration fails; ep is then freed by the caller without using\nep->re_id. Remove the later duplicate assignment in rpcrdma_ep_create()."
    }
  ],
  "lastModified": "2026-08-17T06:19:14.683",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}