CVE-2026-72014

Source
https://cve.org/CVERecord?id=CVE-2026-72014
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72014.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72014
Downstream
Published
2026-08-15T05:51:42.741Z
Modified
2026-08-18T03:56:17.901550154Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
drbd: reject data replies with an out-of-range payload size
Details

In the Linux kernel, the following vulnerability has been resolved:

drbd: reject data replies with an out-of-range payload size

recvdlessread() receives a PDATAREPLY from a peer into the bio of an outstanding read request. The peer-supplied payload length reaches it as the signed int datasize, and two peer-controlled inputs can make it negative. With a negotiated data-integrity-alg the digest length is subtracted first, so a reply whose payload is smaller than the digest underflows datasize. With no integrity algorithm (the default) datasize is assigned from the unsigned h95/h100 wire length and drbdd() never bounds it for a payload-carrying command, so a length above INTMAX casts it negative; this path needs no non-default feature. The bio receive loop then computes expect = mint(int, datasize, bvlen), which is negative, and drbdrecvallwarn(mapped, expect) receives with a sizet of SIZEMAX into the first mapped page.

The sibling receive path readinblock() is not affected: it uses an unsigned size and rejects it against DRBDMAXBIO_SIZE before receiving. Reject a data reply whose size is negative after the optional digest subtraction, covering both triggers.

Impact: a malicious or man-in-the-middle DRBD peer copies attacker-chosen bytes past a bio page in the receiver, corrupting kernel memory. A node that reads from its peer (a diskless node, or read-balancing to the peer) is exposed in the default configuration; data-integrity-alg is not required.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72014.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b411b3637fa71fce9cf2acf0639009500f5892fe
Fixed
bca33f5442c3094511719d9db792ce3165d87e76
Fixed
741a682535deffe9ab7e5c89caf83571efbc9dd9
Fixed
f14e87d7b166490bceb9603b39310e51595d05b9
Fixed
f16866c62656865854106b79bcf6e4ca97a51a92
Fixed
5f59a8142000f0b8f75c432209ead73c424a745d
Fixed
38cc4867540ae8beedfe41a1a1a6ed37052c77d6
Fixed
648d4317326e6aa3f8c05cbf0fd14cc2eba6ca99
Fixed
bd910a7660d280595ef94cb6d193951d855d330f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72014.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.33
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72014.json"