{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-72014","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-09T03:40:39.899Z","datePublished":"2026-08-15T05:51:42.741Z","dateUpdated":"2026-08-17T05:39:26.031Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:39:26.031Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrbd: reject data replies with an out-of-range payload size\n\nrecv_dless_read() receives a P_DATA_REPLY from a peer into the bio of an\noutstanding read request. The peer-supplied payload length reaches it as\nthe signed int data_size, and two peer-controlled inputs can make it\nnegative. With a negotiated data-integrity-alg the digest length is\nsubtracted first, so a reply whose payload is smaller than the digest\nunderflows data_size. With no integrity algorithm (the default) data_size\nis assigned from the unsigned h95/h100 wire length and drbdd() never\nbounds it for a payload-carrying command, so a length above INT_MAX casts\nit negative; this path needs no non-default feature. The bio receive loop\nthen computes expect = min_t(int, data_size, bv_len), which is negative,\nand drbd_recv_all_warn(mapped, expect) receives with a size_t of SIZE_MAX\ninto the first mapped page.\n\nThe sibling receive path read_in_block() is not affected: it uses an\nunsigned size and rejects it against DRBD_MAX_BIO_SIZE before receiving.\nReject a data reply whose size is negative after the optional digest\nsubtraction, covering both triggers.\n\nImpact: a malicious or man-in-the-middle DRBD peer copies attacker-chosen\nbytes past a bio page in the receiver, corrupting kernel memory. A node\nthat reads from its peer (a diskless node, or read-balancing to the peer)\nis exposed in the default configuration; data-integrity-alg is not\nrequired."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - Exploitation is delivered over the DRBD replication TCP protocol when a victim node receives a malicious P_DATA_REPLY from its peer or a man-in-the-middle on that link; recv_dless_read() is reached from drbdd() without any local syscall or ioctl on the victim.\nAC:L - The peer fully controls the wire length in the P_DATA_REPLY header, and two independent triggers (unsigned-to-signed overflow or digest subtraction underflow) deterministically force expect negative so drbd_recv_all_warn() receives SIZE_MAX bytes whenever the victim issues a remote read.\nPR:N - No account, capability, or administrative access on the victim host is required; a malicious DRBD peer or network man-in-the-middle on the replication link can send the crafted reply after connection setup, and cram-hmac-alg peer authentication is optional.\nUI:N - No end-user action is needed because diskless-primary and read-balancing configurations automatically send P_DATA_REQUEST packets to the peer, and the malicious P_DATA_REPLY is processed in the kernel receiver thread during normal I/O.\nS:U - The out-of-bounds socket receive corrupts kernel memory on the same host that runs DRBD; successful exploitation yields kernel compromise on that node but does not by itself cross a VM, container, or IOMMU security boundary.\nC:H - Receiving up to SIZE_MAX attacker-controlled bytes past the mapped bio page is an out-of-bounds kernel write that can corrupt adjacent heap or page data and be leveraged for arbitrary kernel memory disclosure, not merely a bounded leak.\nI:H - The bug copies attacker-chosen network data beyond the allocated bio buffer boundary, providing a kernel out-of-bounds write primitive that can corrupt kernel structures and enable arbitrary code execution or privilege escalation.\nA:H - Writing gigabytes past a bio page can immediately corrupt critical kernel memory and cause oops or panic, and repeated malicious replies can keep the node unavailable even before full exploitation."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/block/drbd/drbd_receiver.c"],"versions":[{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"bca33f5442c3094511719d9db792ce3165d87e76","status":"affected","versionType":"git"},{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"741a682535deffe9ab7e5c89caf83571efbc9dd9","status":"affected","versionType":"git"},{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"f14e87d7b166490bceb9603b39310e51595d05b9","status":"affected","versionType":"git"},{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"f16866c62656865854106b79bcf6e4ca97a51a92","status":"affected","versionType":"git"},{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"5f59a8142000f0b8f75c432209ead73c424a745d","status":"affected","versionType":"git"},{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"38cc4867540ae8beedfe41a1a1a6ed37052c77d6","status":"affected","versionType":"git"},{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"648d4317326e6aa3f8c05cbf0fd14cc2eba6ca99","status":"affected","versionType":"git"},{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"bd910a7660d280595ef94cb6d193951d855d330f","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/block/drbd/drbd_receiver.c"],"versions":[{"version":"2.6.33","status":"affected"},{"version":"0","lessThan":"2.6.33","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.33","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.33","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.33","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.33","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.33","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.33","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.33","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.33","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/bca33f5442c3094511719d9db792ce3165d87e76"},{"url":"https://git.kernel.org/stable/c/741a682535deffe9ab7e5c89caf83571efbc9dd9"},{"url":"https://git.kernel.org/stable/c/f14e87d7b166490bceb9603b39310e51595d05b9"},{"url":"https://git.kernel.org/stable/c/f16866c62656865854106b79bcf6e4ca97a51a92"},{"url":"https://git.kernel.org/stable/c/5f59a8142000f0b8f75c432209ead73c424a745d"},{"url":"https://git.kernel.org/stable/c/38cc4867540ae8beedfe41a1a1a6ed37052c77d6"},{"url":"https://git.kernel.org/stable/c/648d4317326e6aa3f8c05cbf0fd14cc2eba6ca99"},{"url":"https://git.kernel.org/stable/c/bd910a7660d280595ef94cb6d193951d855d330f"}],"title":"drbd: reject data replies with an out-of-range payload size","x_generator":{"engine":"bippy-1.2.0"}}}}