9.1

CVE-2026-64319

nvmet-auth: validate reply message payload bounds against transfer length

In the Linux kernel, the following vulnerability has been resolved:

nvmet-auth: validate reply message payload bounds against transfer length

nvmet_auth_reply() accesses the variable-length rval[] array using
attacker-controlled hl (hash length) and dhvlen (DH value length) fields
without verifying they fit within the allocated buffer of tl bytes.

A malicious NVMe-oF initiator can craft a DHCHAP_REPLY message with a
small transfer length but large hl/dhvlen values, causing out-of-bounds
heap reads when the target processes the DH public key (rval + 2*hl) or
performs the host response memcmp.

With DH authentication configured, the OOB pointer is passed directly to
sg_init_one() and read by crypto_kpp_compute_shared_secret(), reaching
up to 526 bytes past the buffer. This is exploitable pre-authentication.

Add bounds validation ensuring sizeof(*data) + 2*hl + dhvlen <= tl before
any access to the variable-length fields.

Discovered by Atuin - Automated Vulnerability Discovery Engine.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < 80cd28b56ab62d3e7ed0a7bf05282e6d3ee5b2a0
Status affected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < 999f6205ede984a786f35f727b01f971b98e215d
Status affected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < 6d7649c1231dac14d906985d2936967e23041c26
Status affected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < caa71b3a43ea5c13fe7141cb019ebcb03b8ac857
Status affected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < 3a413ece2504c70aa34a20be4dafec04e8c741f9
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.0
Status affected
Version 0
Version < 6.0
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.96
Status unaffected
Version <= 6.18.*
Version 6.18.39
Status unaffected
Version <= 7.1.*
Version 7.1.4
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.413
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/80cd28b56ab62d3e7ed0a7bf05282e6d3ee5b2a0
https://git.kernel.org/stable/c/999f6205ede984a786f35f727b01f971b98e215d
https://git.kernel.org/stable/c/6d7649c1231dac14d906985d2936967e23041c26
https://git.kernel.org/stable/c/caa71b3a43ea5c13fe7141cb019ebcb03b8ac857
https://git.kernel.org/stable/c/3a413ece2504c70aa34a20be4dafec04e8c741f9