Skip to main content
Vulnerability Database/CVE-2026-13087

CVE-2026-13087: Linux Kernel RPC-over-RDMA Buffer Overflow

CVE-2026-13087 is a heap buffer overflow in the Linux kernel's RPC-over-RDMA server that can cause system crashes or enable code execution. This article covers the technical details, affected versions, and mitigation strategies.

Published:

CVE-2026-13087 Overview

CVE-2026-13087 is a heap out-of-bounds write vulnerability in the Linux kernel's RPC-over-RDMA server reply path. The flaw resides in net/sunrpc/xprtrdma/svc_rdma_sendto.c and affects Network File System (NFS) servers exposing RDMA transports. An authenticated remote client can trigger a kernel heap overflow by sending a crafted large NFS READ request with an empty Write list and no Reply chunk. The server linearizes the multi-page reply into a fixed-size 4096-byte heap buffer without bounds checking. Exploitation can cause kernel crashes or potential arbitrary code execution through adjacent heap object corruption [CWE-787].

Critical Impact

Remote attackers with low privileges can crash the kernel or corrupt adjacent heap objects, enabling denial of service or potential code execution against NFS-over-RDMA servers.

Affected Products

  • Linux kernel net/sunrpc/xprtrdma/svc_rdma_sendto.c (RPC-over-RDMA server component)
  • Linux distributions shipping NFS server with RDMA transport support
  • Red Hat Enterprise Linux (see Red Hat CVE-2026-13087 Advisory)

Discovery Timeline

  • 2026-09-22 - CVE-2026-13087 published to the National Vulnerability Database (NVD)
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-13087

Vulnerability Analysis

The vulnerability affects the SUNRPC subsystem that implements Remote Procedure Call (RPC) transport over Remote Direct Memory Access (RDMA). The server-side send path in svc_rdma_sendto.c prepares NFS READ responses by linearizing scattered reply pages into a contiguous buffer for transmission. When a client submits an RPC-over-RDMA request that omits both a Write list and a Reply chunk, the server falls back to inline reply handling. That inline path uses a fixed 4096-byte heap allocation as the destination buffer but does not validate the total size of the reply payload before copying. Large NFS READ replies therefore write past the end of the allocation, corrupting adjacent kernel slab objects.

Root Cause

The root cause is a missing bounds check in the reply linearization logic. The code assumes inline replies fit within a single page-sized buffer because well-formed clients negotiate a Write list or Reply chunk for large transfers. A malicious client can violate that assumption by crafting a READ request whose response exceeds 4096 bytes while advertising no chunks, forcing the server to copy oversized data into the fixed buffer.

Attack Vector

Exploitation requires network reachability to an NFS server exposing an RDMA transport and valid credentials to issue NFS READ operations. The attacker crafts an RPC-over-RDMA header with an empty Write list and no Reply chunk, then requests a READ of sufficient length to overflow the 4096-byte destination buffer. The resulting heap corruption can panic the kernel or, with heap grooming, overwrite adjacent objects to influence kernel control flow.

No verified public proof-of-concept code is available for CVE-2026-13087. Consult the Red Hat Bug Report #2470788 for upstream analysis and reproduction details.

Detection Methods for CVE-2026-13087

Indicators of Compromise

  • Kernel oops or panic messages referencing svc_rdma_sendto, svc_rdma_send_reply_msg, or SUNRPC RDMA stack frames in dmesg and /var/log/messages.
  • SLUB or KASAN reports indicating out-of-bounds writes in the sunrpc or rpcrdma modules.
  • Unexpected termination or restarts of the nfsd service on hosts exposing RDMA transports.

Detection Strategies

  • Enable KASAN on non-production kernels to surface out-of-bounds writes during fuzzing or staged rollouts.
  • Deploy endpoint telemetry to capture kernel crash events, NFS service restarts, and RDMA connection anomalies from suspected clients.
  • Correlate NFS READ traffic patterns with abnormally small chunk lists to identify malformed RPC-over-RDMA requests.

Monitoring Recommendations

  • Monitor RDMA-capable interfaces (rdma link show, rdma statistic) for unusual peer activity and connection resets.
  • Alert on nfsd process crashes and kernel taint flag changes via host-based monitoring.
  • Track authentication and mount events against NFS-over-RDMA exports to identify unexpected client sources.

How to Mitigate CVE-2026-13087

Immediate Actions Required

  • Apply the kernel updates published by your Linux distribution as soon as they are available; track status through the Red Hat CVE-2026-13087 Advisory.
  • Restrict NFS-over-RDMA exports to trusted client subnets using firewall rules and RDMA subnet management policies.
  • Audit which hosts expose nfsd over RDMA and disable the transport where it is not required.

Patch Information

At the time of publication, upstream and distribution patches are tracked through the referenced Red Hat advisory and Bugzilla entry. Administrators should install the fixed kernel packages once released by their vendor and reboot affected NFS servers. Confirm the running kernel version with uname -r after patching.

Workarounds

  • Disable the RPC-over-RDMA server transport by unloading the svcrdma module: rmmod svcrdma and prevent auto-load via /etc/modprobe.d/.
  • Serve NFS exports over TCP instead of RDMA until the kernel is patched.
  • Enforce network segmentation so only vetted RDMA clients can reach NFS server ports.
bash
# Prevent the RPC-over-RDMA server module from loading
echo "blacklist svcrdma" | sudo tee /etc/modprobe.d/blacklist-svcrdma.conf
sudo rmmod svcrdma 2>/dev/null || true

# Verify NFS server is no longer advertising RDMA transport
cat /proc/fs/nfsd/portlist | grep -i rdma

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.