# CVE-2026-62816 — Windows Reliable Multicast Transport Driver `rmcast.sys` NAK-Index Offset Integer Overflow → Heap Buffer Overflow (RCE)

---

## Summary

| | |
|---|---|
| **Product** | Windows — `rmcast.sys` (Reliable Multicast Transport Driver / PGM — Pragmatic General Multicast) |
| **CVE ID** | CVE-2026-62816 |
| **Impact** | Remote Code Execution (unauthenticated, adjacent network) |
| **MSRC severity** | Critical |
| **CVSS** | 8.8 / 7.7 — `CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C` |
| **CWE** | CWE-190: Integer Overflow or Wraparound → CWE-122: Heap-based Buffer Overflow |
| **Delivery** | Adjacent network — crafted PGM/RMCAST packets (NAK) to the multicast transport |
| **KB / Fixed build** | KB5121003 — `rmcast.sys` 10.0.26100.9168 (Win11 24H2 x64) |
| **Patch Date** | August 11, 2026 (2026-Aug) |
| **Pre-patch binary** | `rmcast.sys` 10.0.26100.8972 — SHA256 `22211a0ca72d952c0d96e542153ac68158c4620c2f57bb08abfad1f94f6ba77e` |
| **Post-patch binary** | `rmcast.sys` 10.0.26100.9168 — SHA256 `8d8463382d7d33b129f8f428e93ffec05721b631d5f4ba1131086adbc16679a9` |
| **Feature flag** | `Feature_4002387257` — **the fix is CFR-gated** |
| **Exploitability** | Exploitation Less Likely; not publicly disclosed; not exploited (per MSRC) |

---

## Product Description

`rmcast.sys` is the Windows **Reliable Multicast Transport Driver**, implementing
**PGM (Pragmatic General Multicast)**. Reliability is provided through a send window
and **NAK** (negative-acknowledgement) driven retransmission: when a receiver reports
a missing sequence number, the sender retransmits **repair data (RData)** for that
sequence. `PgmSendRData` builds and copies the repair-data packet; `AdvanceWindow`
and `SendNextPacket` maintain the transmit window.

---

## Vulnerability Summary

When `PgmSendRData` services a received NAK, it derives an index from the NAK
(`GetNextNakIndex`) and combines it into `local_a4`, then computes the repair-data
buffer offset as roughly `(local_a4 - window_trail) * per_packet_stride`. Because the
NAK-derived index is **attacker-influenced** and the subtraction/multiplication were
performed without adequate range validation, a crafted NAK can drive that arithmetic
to **wrap (CWE-190)**, producing a miscalculated offset/length that is then used for
the repair-data copy — an out-of-bounds **heap buffer overflow (CWE-122)**. Because
RMCAST processes multicast packets **without authentication over an adjacent
network** (`AV:A`, `PR:N`, `UI:N`), the overwrite is a remote code-execution
primitive (Microsoft rates it **Critical, 8.8**).

> Confirmation level: this August update is a **substantial rework** of the PGM send
> path (`PgmSendRData`, `AdvanceWindow`, `SendNextPacket`, `DestroyEntry`; 3 code
> changes + 2 new helpers) under the dominant flag `Feature_4002387257`. The isolable
> mechanism is the **range-validation of the NAK-derived index `local_a4` before the
> offset multiply and repair-data copy**; it is stated here at confirmed-changed level.

---

## Prerequisites and Constraints

- Adjacent network, unauthenticated (`AV:A`, `AC:L`, `PR:N`, `UI:N`): send crafted
  PGM/RMCAST NAK traffic to a host running the Reliable Multicast transport.
- The NAK requests a sequence whose derived index overflows the
  `(index - trail) * stride` offset arithmetic in `PgmSendRData`.
- Result: repair data is copied using a miscalculated offset/length → heap overflow.

---

## Vulnerability Details

### Root Cause

The NAK-derived index (`local_a4`) used to locate/size repair data was combined and
scaled (`(local_a4 - trail) * stride`) without validating its range, so a crafted NAK
could wrap the computation and yield an out-of-bounds destination/length for the
repair-data copy.

### The patch (confirmed — diff, .8972 → .9168)

The diff shows `PgmSendRData` (with `AdvanceWindow` / `SendNextPacket`) reworked and
gated behind `Feature_4002387257`. The repair-data copy is converted from `memmove`
to a bounds-tracked `memcpy`, and the NAK-derived index `local_a4` is validated
before it drives the offset multiply:

```c
// PgmSendRData (10.0.26100.9168) — PATCHED (from the diff)
local_a4 = uVar15;
cVar7 = GetNextNakIndex((longlong)param_2, (char *)local_a7);   // NAK-derived index
local_a4 = uVar15 + local_a7[0];
uVar9 = Feature_4002387257__private_IsEnabled();
if (uVar9 /* && range-validate local_a4 */) {
    // guarded offset computation:
    uVar13 = (ulonglong)((local_a4 - *(int *)(lVar2 + 0xa0)) * *(int *)(lVar2 + 0x6c)) + ...;
    uVar15 = local_a4 - *(int *)(lVar2 + 0xa0);
    ...
    memcpy(_Dst, local_90 + 0x10, (ulonglong)uVar17);          // was: memmove(_Dst, puVar13+0x10, *puVar13)
}
```

Pre-patch, the `(local_a4 - trail) * stride` offset was computed and used to copy
repair data without validating `local_a4`, so a crafted NAK index could overflow the
arithmetic and drive the copy out of bounds. With the flag enabled, the index is
range-checked before the offset multiply and the copy is length-bounded, closing the
integer-overflow-to-heap-overflow.

### Patch Completeness Assessment

**CFR-gated behind `Feature_4002387257`.** The validated PGM send path runs only when
the flag is enabled; the original arithmetic still ships when disabled. Verify
`Feature_4002387257` is enabled to confirm the fix is live. Given unauthenticated RCE
over an adjacent network, apply KB5121003 or later regardless.

---

## Detection Guidance

**Behavioural.** Pool corruption / bugcheck crashes in `rmcast!PgmSendRData` /
`AdvanceWindow` / `SendNextPacket` on unpatched/flag-disabled builds, correlated with
inbound PGM (IP protocol 113) / RMCAST multicast traffic — especially bursts of NAKs
requesting out-of-range sequence numbers. Restrict PGM/RMCAST exposure to untrusted
network segments; disable the Reliable Multicast (MSMQ/PGM) feature where unused.

**Config.** The fix is CFR-gated — confirm `Feature_4002387257` is enabled.

---

## References

- MSRC advisory — CVE-2026-62816 (Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution), released 2026-08-11, KB5121003.
- Full binary diff: `/data/patch_diffs/rmcast_sys-cve-2026-62816-ghidriff.md`
