CVE-2026-72217
CVE CVE-2026-72217EUVD EUVD-2026-58975Veröffentlicht 2026-08-15T05:54:10.000ZZuletzt geändert 2026-08-17T05:41:40.000ZCVSS 9.8
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing xdr_buf_to_bvec() writes a bio_vec into the caller's array before testing whether that slot is in range, and the head branch performs the store with no check at all. When the caller's budget is exactly used up, the next store lands one element past the end of the array. The overflow label returns count - 1, which masks the surplus store but cannot undo it. rq_bvec, the array passed by nfsd_vfs_write(), is allocated to exactly rq_maxpages entries with no slack. The OOB store can land in adjacent slab memory; the bv_len and bv_offset fields written there are derived from client-supplied RPC payload sizes. Move the in-range check ahead of the store in the head, page-loop, and tail branches. With the check at the top of each sequence, count is incremented only after a successful store, so the overflow label can return count directly.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 2eb2b93581813b74c7174961126f6ec38eadb5a7 <6029e711a818bf34d6c4b90cafee24f3afffa110; patch: 6.18.40; 6.6; patch: 7.2; 2eb2b93581813b74c7174961126f6ec38eadb5a7 <4a1148f2739d5089c3ca8ae2e9d1053e219ab5df; patch: 6.12.97; patch: 7.1.5; patch: 0; patch: 6.6.145; 2eb2b93581813b74c7174961126f6ec38eadb5a7 <69e18135e2a004a79505451dbef07314ea16e1eb; 2eb2b93581813b74c7174961126f6ec38eadb5a7 <42f5b80dda6b86e424054baf1475df686c403d5c; 2eb2b93581813b74c7174961126f6ec38eadb5a7 <98414b42530af65cb984ffc12685096a3b5e179a
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.