---
id: CVE-2026-13087
title: >-
  A heap out-of-bounds write vulnerability was found in the Linux kernel's
  RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c
summary: >-
  A heap out-of-bounds write vulnerability was found in the Linux kernel's
  RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When
  a crafted RPC-over-RDMA client sends a large NFS READ request with an empty
  Write lis…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: Red Hat
product: kernel
affected:
  - kernel (all versions)
  - kernel (all versions)
  - kernel (all versions)
  - kernel-rt (all versions)
  - kernel (all versions)
  - kernel-rt (all versions)
  - kernel (all versions)
  - kernel-rt (all versions)
  - kernel (all versions)
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:37:36.747'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13087'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-13087'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2470788'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2470788'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13087.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-13087'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13087'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-22T17:58:21.616726Z'
ingestedAt: '2026-09-22T17:07:07.378Z'
epss: 0.00471
epssPercentile: 0.38029
---

## Overview

A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large NFS READ request with an empty Write list and no Reply chunk, the server linearizes the entire multi-page reply into a fixed-size 4096-byte heap buffer without bounds checking, resulting in a kernel heap overflow. This can lead to denial of service via kernel crash or potential code execution through corruption of adjacent kernel heap objects.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux for NVIDIA 26 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13087.json)
