Skip to content
VulniPulse
Advisory severityHigh8.1Red Hat Linux

High [CVE-2026-72129] handle inline data with a nonzero offset

This high-severity Red Hat Linux advisory covers CVE-2026-72129 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-72129 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxLinux Kernel
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: handle inline data with a nonzero offset nvmet_rdma_use_inline_sg() maps the host-controlled inline data offset into the per-command inline scatterlist.

The bounds check admits any offset with off + len offset = off; sg->length = min_t(int, len, PAGE_SIZE - off); When a port is configured with inline_data_size > PAGE_SIZE (settable up to max(SZ_16K, PAGE_SIZE)), an offset in (PAGE_SIZE, inline_data_size] makes "PAGE_SIZE - off" underflow, so sg->length is set to ~4 GiB and the block backend reads far past the first inline page. num_pages(len) also ignores the offset, so an in-bounds offset whose [off, off+len) span crosses a page boundary under-counts the scatterlist.

Map the offset properly: split it into a page index and an in-page offset, start the scatterlist at that page, and size the page count from page_off + len.

Because the request scatterlist may now start at inline_sg[page_idx] rather than inline_sg[0], generalize the inline-SGL identity test in nvmet_rdma_release_rsp() to a range test; otherwise the persistent inline scatterlist is mistaken for an allocated one and nvmet_req_free_sgls() frees an inline page (and warns in free_large_kmalloc()).

This vulnerability arises from incorrect handling of inline data with a non-zero offset, which can lead to an integer underflow.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 23 days ago·verify at source

Fixed versions
  • kernel-0:6.12.0-211.53.1.el10_2
  • kernel-rt-0:4.18.0-553.160.1.rt7.501.el8_10
  • kernel-0:4.18.0-553.160.1.el8_10
  • kernel-0:5.14.0-687.46.1.el9_8
  • RHSA-2026:65334
  • RHSA-2026:64770
  • RHSA-2026:66000
  • RHSA-2026:66180

Official advisory · high-confidence parse· fetched 23 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this issue, prevent the `nvmet_rdma` kernel module from loading if NVMe over RDMA functionality is not required. This can be achieved by creating a modprobe configuration file. 1. Create a file named `/etc/modprobe.d/disable-nvmet_rdma.conf` with the following content: ``` install nvmet_rdma /bin/true ``` 2. Regenerate the initramfs to ensure the change takes effect on boot: ```bash dracut -f -v ``` 3. Reboot the system for the changes to be fully applied. This mitigation may impact systems that rely on NVMe over RDMA for storage operations. If NVMe over RDMA is in use, consider configuring `inline_data_size` to be less than or equal to `PAGE_SIZE` if your workload permits, though this might affect performance.

Official advisory · high-confidence parse· fetched 23 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.