9.8

CVE-2026-72129

nvmet-rdma: handle inline data with a nonzero offset

In the Linux kernel, the following vulnerability has been resolved:

nvmet-rdma: handle inline data with a nonzero offset

nvmet_rdma_use_inline_sg() maps the host-controlled inline data offset
into the per-command inline scatterlist.  The bounds check admits any
offset with off + len <= inline_data_size, but the mapping still assumes
the data begins in the first inline page:

	sg->offset = off;
	sg->length = min_t(int, len, PAGE_SIZE - off);

When a port is configured with inline_data_size > PAGE_SIZE (settable up
to max(SZ_16K, PAGE_SIZE)), an offset in (PAGE_SIZE, inline_data_size]
makes "PAGE_SIZE - off" underflow, so sg->length is set to ~4 GiB and
the block backend reads far past the first inline page.  num_pages(len)
also ignores the offset, so an in-bounds offset whose [off, off+len)
span crosses a page boundary under-counts the scatterlist.

Map the offset properly: split it into a page index and an in-page
offset, start the scatterlist at that page, and size the page count from
page_off + len.  Because the request scatterlist may now start at
inline_sg[page_idx] rather than inline_sg[0], generalize the inline-SGL
identity test in nvmet_rdma_release_rsp() to a range test; otherwise the
persistent inline scatterlist is mistaken for an allocated one and
nvmet_req_free_sgls() frees an inline page (and warns in
free_large_kmalloc()).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349
Version < c2106ba1b14d644a5203bea1a50dbe25dcad713c
Status affected
Version 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349
Version < bf8bcc1c137d54a62a428b00051fdbb13660673b
Status affected
Version 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349
Version < 11401371152b228448a41d79c6de1c938f93049a
Status affected
Version 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349
Version < 7c96581169c9d9a7d0726e554313acfbead6141c
Status affected
Version 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349
Version < 42a8ea3acd883f4f210d9e54e0975b1e2292b529
Status affected
Version 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349
Version < 2944113ad5fbcdf5d349d857c03d2a44b6de75b8
Status affected
Version 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349
Version < 98bcdfa619150b2f41fa15bac140dbaf2584ad05
Status affected
Version 0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349
Version < 48c0162f647bb47e6084ffbc71b8f213f5e2f4f8
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.19
Status affected
Version 0
Version < 4.19
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.7% 0.503
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/c2106ba1b14d644a5203bea1a50dbe25dcad713c
https://git.kernel.org/stable/c/bf8bcc1c137d54a62a428b00051fdbb13660673b
https://git.kernel.org/stable/c/11401371152b228448a41d79c6de1c938f93049a
https://git.kernel.org/stable/c/7c96581169c9d9a7d0726e554313acfbead6141c
https://git.kernel.org/stable/c/42a8ea3acd883f4f210d9e54e0975b1e2292b529
https://git.kernel.org/stable/c/2944113ad5fbcdf5d349d857c03d2a44b6de75b8
https://git.kernel.org/stable/c/98bcdfa619150b2f41fa15bac140dbaf2584ad05
https://git.kernel.org/stable/c/48c0162f647bb47e6084ffbc71b8f213f5e2f4f8