PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72473 Linux CVE debrief

A vulnerability in the Linux kernel's xprtrdma module has been resolved. The issue involves decoupling req recycling from RPC completion to prevent premature freeing of rpcrdma_req structures. This change ensures proper handling of req structures and prevents potential crashes or security issues. Linux kernel developers, administrators, and users who rely on the xprtrdma module should review and apply the provided kernel patches to address the vulnerability.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers, administrators, and users who rely on the xprtrdma module should be aware of this vulnerability. They should review and apply the provided kernel patches to address the issue. Additionally, they should monitor Linux kernel updates for any related security advisories and consider implementing compensating controls to detect and prevent potential exploitation. The vulnerability affects operators, platforms, and security teams that use the xprtrdma module in their Linux kernel deployments. They should assess their exposure and take necessary actions to mitigate the vulnerability. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and planning vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions, retested remediated assets, and closed items should be tracked, with evidence documented before closing the item. Asset inventory and source tracking are crucial in this process. Rolling back change windows and considering source tracking can also help in managing the vulnerability effectively. The vulnerability management team should prioritize patching and ensure that all necessary steps are taken to prevent exploitation. This includes verifying that the patches are applied correctly and testing the systems to ensure that the vulnerability is not still exploitable. The security team should also review the vulnerability and assess the risk to the organization, and provide guidance on how to mitigate the vulnerability and prevent similar issues in the future. The team should also consider implementing additional security controls, such as monitoring and detection systems, to help identify and respond to potential security incidents. By taking these steps, organizations can help protect their systems and prevent exploitation of this vulnerability. The debrief provides an overview of the vulnerability, its impact, and the

Technical summary

The vulnerability is related to the xprtrdma module in the Linux kernel. The issue involves the improper handling of req recycling and RPC completion, which could lead to premature freeing of rpcrdma_req structures. The fix decouples req recycling from RPC completion and introduces additional checks to ensure proper handling of req structures. This change affects Linux kernel developers, administrators, and users who rely on the xprtrdma module. They should review and apply the provided kernel patches to ensure the vulnerability is addressed.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the provided kernel patches to ensure the vulnerability is addressed
  • Monitor Linux kernel updates for any related security advisories
  • Consider implementing compensating controls to detect and prevent potential exploitation
  • Perform source tracking to manage the vulnerability effectively
  • Review and test compensating controls for exposed systems
  • Monitor relevant logs and detection systems for potential security incidents
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is related to the xprtrdma module in the Linux kernel. The issue involves the improper handling of req recycling and RPC completion, which could lead to premature freeing of rpcrdma_req structures. The fix decouples req recycling from RPC completion and introduces additional checks to ensure proper handling of req structures.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72473 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72473

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72473 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72473

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/53442c7d0c888e51b8bc3da196970a669cc6b294

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/740975054a1970c0cf15f70ac39724a064f45847

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8203f760a72bd39a3b66bc4eff0aa272a99fe22b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9f3d9b68c1c6c51746e5ecdb52b2e6a2901de37e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e7632089523acddcdd8f090ad19e96fb3107b04d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e786233d2e0bbff9a82e43f02ae3a46ab4b08ec3

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.