CRITICAL Introduced in 6.6
sunrpc BioVec OOB
CVE-2026-72217
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI9.6CRITICAL
01Description
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing xdr_buf_to_bvec() writes a bio_vec into the caller's array before testing whether that slot is in range, and the head branch performs the store with no check at all. When the caller's budget is exactly used up, the next store lands one element past the end of the array. The overflow label returns count - 1, which masks the surplus store but cannot undo it. rq_bvec, the array passed by nfsd_vfs_write(), is allocated to exactly rq_maxpages entries with no slack. The OOB store can land in adjacent slab memory; the bv_len and bv_offset fields written there are derived from client-supplied RPC payload sizes. Move the in-range check ahead of the store in the head, page-loop, and tail branches. With the check at the top of each sequence, count is incremented only after a successful store, so the overflow label can return count directly.
02KernelScan AI Analysis
Risk summary
A remote attacker sending crafted NFS RPC write requests to a server can trigger an out-of-bounds write in the kernel's SUNRPC XDR buffer-to-bio_vec conversion, corrupting adjacent slab memory with attacker-controlled values. This can lead to kernel memory disclosure, data corruption, or a system crash. Any system running an affected kernel with an NFS server exposed to network clients is at risk.
Vulnerability analysis
When an NFS server processes a client's write request, it converts the RPC payload's XDR buffer into an array of bio_vec entries for I/O. The conversion function writes each bio_vec into the caller's array before checking whether that slot is within bounds, and one code path performs the write with no check at all. When the array's capacity is exactly consumed, the next write lands one element past the end, corrupting adjacent slab memory with length and offset values derived from the client-supplied payload sizes. The fix moves the bounds check ahead of every store so that no write occurs unless the slot is confirmed in range, and the overflow path returns the accurate count without masking the surplus write. The vulnerable path is reachable by any network client that can send NFS write RPCs to the server — no server-side account or special privileges are required.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.6 | 6.6 | 6.6.145 | 4a1148f2739d |
| 6.12 | 6.6 | 6.12.97 | 6029e711a818 |
| 6.18 | 6.6 | 6.18.40 | 69e18135e2a0 |
| mainline | 6.6 | 7.2-rc1 | 42f5b80dda6b |
| 7.1 | 6.6 | 7.1.5 | 98414b42530a |