Database/Firmware, BMC & network fabric
Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range): The inline copy path adds a page index where it
CVSS 9.8CVE-2025-68811Firmware, BMC & network fabriccurated
Impact
The inline copy path adds a page index where it should add a byte offset, so memcpy lands outside the current page and writes into unrelated kernel memory on the NFS server. Triggered by ordinary RDMA inline traffic from a client.
Who can reach it
Any NFS/RDMA client that can reach the storage server over the fabric.
What to do
Update the storage server kernel to one carrying the rc_pageoff fix and reboot. Serve affected exports over TCP as a stopgap.
References
Related entries
- Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range): svc_rdma_copy_inline_range indexes rq_pages with anCVE-2025-71068 · Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range)Critical
- Linux RDMA/srpt: failed multi-buffer descriptor setup leaves stale counters and a dangling rw_ctxs pointerCVE-2026-100075 · Linux kernel RDMA/srpt (SRP target, srpt_alloc_rw_ctxs unwind)Critical
- Cisco Nexus 9000: unauthenticated remote code execution as root via Silicon One ports in the default L3 VRFCVE-2026-20212 · Cisco Nexus 9000 NX-OS Silicon One integration (S1HAL, TCP 43210/43211)Critical
- Linux kernel nvmet-tcp - PDU iovec construction and H2C Transfer Tag handling: nvmet_tcp_build_pdu_iovec() walks pastCVE-2026-23112 · Linux kernel nvmet-tcp - PDU iovec construction and H2C Transfer Tag handlingCritical
- Linux kernel (drivers/infiniband/core): The iWARP connection manager returns work items to a free list while the sameCVE-2026-45898 · Linux kernel (drivers/infiniband/core)Critical
- Linux kernel - RDMA/rxe memory region translation, drivers/infiniband/sw/rxe/rxe_mr.c: Rxe mishandles memory regionsCVE-2026-46325 · Linux kernel - RDMA/rxe memory region translation, drivers/infiniband/sw/rxe/rxe_mr.cCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.