CVE-2026-72129
Linux kernel nvmet-rdma bounds bug allows out-of-bounds read and memory corruption
Is CVE-2026-72129 being exploited?
Not confirmed. CVE-2026-72129 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.69% probability of exploitation in the next 30 days.
How severe is CVE-2026-72129?
CVE-2026-72129 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72129?
Yes. A fix has been recorded for CVE-2026-72129. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72129 affect?
CVE-2026-72129 affects Linux kernel with nvmet-rdma (NVMe over Fabrics RDMA targets). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72129?
Apply kernel security updates/backport fix; restrict or disable NVMe-oF RDMA access until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote NVMe-oF (RDMA) initiator can trigger out-of-bounds reads, leading to data disclosure, crashes and potential privilege escalation.
Immediate action required
- affected>= 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349 and < c2106ba1b14d644a5203bea1a50dbe25dcad713c
- affected>= 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349 and < bf8bcc1c137d54a62a428b00051fdbb13660673b
- affected>= 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349 and < 11401371152b228448a41d79c6de1c938f93049a
- affected>= 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349 and < 7c96581169c9d9a7d0726e554313acfbead6141c
- affected>= 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349 and < 42a8ea3acd883f4f210d9e54e0975b1e2292b529
- affected>= 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349 and < 2944113ad5fbcdf5d349d857c03d2a44b6de75b8
- affected>= 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349 and < 98bcdfa619150b2f41fa15bac140dbaf2584ad05
- affected>= 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349 and < 48c0162f647bb47e6084ffbc71b8f213f5e2f4f8
- affected4.19
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.