nvmet-rdma: handle inline data with a nonzero offset
Published Aug 15, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.76%
Description
nvmet_rdma_use_inline_sg() maps the host-controlled inline data offset into the per-command inline scatterlist. The bounds check admits any offset with off + len <= inline_data_size, but the mapping still assumes the data begins in the first inline page:
sg->offset = off; sg->length = min_t(int, len, PAGE_SIZE - off);
When a port is configured with inline_data_size > PAGE_SIZE (settable up to max(SZ_16K, PAGE_SIZE)), an offset in (PAGE_SIZE, inline_data_size] makes "PAGE_SIZE - off" underflow, so sg->length is set to ~4 GiB and the block backend reads far past the first inline page. num_pages(len) also ignores the offset, so an in-bounds offset whose [off, off+len) span crosses a page boundary under-counts the scatterlist.
Map the offset properly: split it into a page index and an in-page offset, start the scatterlist at that page, and size the page count from page_off + len. Because the request scatterlist may now start at inline_sg[page_idx] rather than inline_sg[0], generalize the inline-SGL identity test in nvmet_rdma_release_rsp() to a range test; otherwise the persistent inline scatterlist is mistaken for an allocated one and nvmet_req_free_sgls() frees an inline page (and warns in free_large_kmalloc()).
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.19StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.19
- Version 5.10.261StatusunaffectedConstraints<=5.10.*
- Version 5.15.212StatusunaffectedConstraints<=5.15.*
- Version 6.1.178StatusunaffectedConstraints<=6.1.*
- Version 6.12.97StatusunaffectedConstraints<=6.12.*
- Version 6.18.40StatusunaffectedConstraints<=6.18.*
- Version 6.6.145StatusunaffectedConstraints<=6.6.*
- Version 7.1.5StatusunaffectedConstraints<=7.1.*
- Version 7.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel-0:6.12.0-211.53.1.el10_2
Fixed · RHSA-2026:65334
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.160.1.el8_10
Fixed · RHSA-2026:66000
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.160.1.rt7.501.el8_10
Fixed · RHSA-2026:64770
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.46.1.el9_8
Fixed · RHSA-2026:66180
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.46.1.el9_8
Fixed · RHSA-2026:66180
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Affected
Red Hat Enterprise Linux 7
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel-0:6.12.0-211.53.1.el10_2 | Fixed | RHSA-2026:65334 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.160.1.el8_10 | Fixed | RHSA-2026:66000 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.160.1.rt7.501.el8_10 | Fixed | RHSA-2026:64770 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.46.1.el9_8 | Fixed | RHSA-2026:66180 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.46.1.el9_8 | Fixed | RHSA-2026:66180 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
To mitigate this issue, prevent the `nvmet_rdma` kernel module from loading if NVMe over RDMA functionality is not required. This can be achieved by creating a modprobe configuration file. 1. Create a file named `/etc/modprobe.d/disable-nvmet_rdma.conf` with the following content: ``` install nvmet_rdma /bin/true ``` 2. Regenerate the initramfs to ensure the change takes effect on boot: ```bash dracut -f -v ``` 3. Reboot the system for the changes to be fully applied. This mitigation may impact systems that rely on NVMe over RDMA for storage operations. If NVMe over RDMA is in use, consider configuring `inline_data_size` to be less than or equal to `PAGE_SIZE` if your workload permits, though this might affect performance.
References (14)
- https://access.redhat.com/security/cve/CVE-2026-72129 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2516731 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-58887 Advisory
- https://git.kernel.org/stable/c/11401371152b228448a41d79c6de1c938f93049a
- https://git.kernel.org/stable/c/2944113ad5fbcdf5d349d857c03d2a44b6de75b8
- https://git.kernel.org/stable/c/42a8ea3acd883f4f210d9e54e0975b1e2292b529
- https://git.kernel.org/stable/c/48c0162f647bb47e6084ffbc71b8f213f5e2f4f8
- https://git.kernel.org/stable/c/7c96581169c9d9a7d0726e554313acfbead6141c
- https://git.kernel.org/stable/c/98bcdfa619150b2f41fa15bac140dbaf2584ad05
- https://git.kernel.org/stable/c/bf8bcc1c137d54a62a428b00051fdbb13660673b
- https://git.kernel.org/stable/c/c2106ba1b14d644a5203bea1a50dbe25dcad713c
- https://lore.kernel.org/linux-cve-announce/2026081530-CVE-2026-72129-841e@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-72129
- https://www.cve.org/CVERecord?id=CVE-2026-72129
Change history (0)
No recorded changes yet.