Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-72468

Published Aug 15, 2026 EPSS 0.20% (10th pctl)

Overview

CVE-2026-72468 is a known-severity vulnerability. It was published on August 15, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

xprtrdma: Initialize re_id before removal registration

rpcrdma_create_id() registers ep->re_rn with the rpcrdma ib_client

before returning the new rdma_cm_id to rpcrdma_ep_create(). However

rpcrdma_ep_create() currently stores that pointer in ep->re_id only

after rpcrdma_create_id() returns.

A local administrator can race an NFS/RDMA mount against RDMA device

removal. If rpcrdma_remove_one() observes the just-registered

notification before rpcrdma_ep_create() assigns ep->re_id,

rpcrdma_ep_removal_done() calls trace_xprtrdma_device_removal(NULL).

The tracepoint dereferences id->device->name and copies

id->route.addr.dst_addr, so the callback can crash the kernel with a

NULL pointer dereference.

Store the rdma_cm_id in ep->re_id immediately before publishing

ep->re_rn. The existing error path still destroys the id directly if

registration fails; ep is then freed by the caller without using

ep->re_id. Remove the later

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-72468?

CVE-2026-72468 is a known-severity vulnerability. It was published on August 15, 2026.

How severe is CVE-2026-72468?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-72468?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-72468?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-72468 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.