CVE-2026-72217
CVE CVE-2026-72217EUVD EUVD-2026-58975Published 2026-08-15T05:54:10.000ZLast changed 2026-08-17T05:41:40.000ZCVSS 9.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing xdr_buf_to_bvec() writes a bio_vec into the caller's array before testing whether that slot is in range, and the head branch performs the store with no check at all. When the caller's budget is exactly used up, the next store lands one element past the end of the array. The overflow label returns count - 1, which masks the surplus store but cannot undo it. rq_bvec, the array passed by nfsd_vfs_write(), is allocated to exactly rq_maxpages entries with no slack. The OOB store can land in adjacent slab memory; the bv_len and bv_offset fields written there are derived from client-supplied RPC payload sizes. Move the in-range check ahead of the store in the head, page-loop, and tail branches. With the check at the top of each sequence, count is incremented only after a successful store, so the overflow label can return count directly.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 2eb2b93581813b74c7174961126f6ec38eadb5a7 <6029e711a818bf34d6c4b90cafee24f3afffa110; patch: 6.18.40; 6.6; patch: 7.2; 2eb2b93581813b74c7174961126f6ec38eadb5a7 <4a1148f2739d5089c3ca8ae2e9d1053e219ab5df; patch: 6.12.97; patch: 7.1.5; patch: 0; patch: 6.6.145; 2eb2b93581813b74c7174961126f6ec38eadb5a7 <69e18135e2a004a79505451dbef07314ea16e1eb; 2eb2b93581813b74c7174961126f6ec38eadb5a7 <42f5b80dda6b86e424054baf1475df686c403d5c; 2eb2b93581813b74c7174961126f6ec38eadb5a7 <98414b42530af65cb984ffc12685096a3b5e179a
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.