-

CVE-2026-80788

Medienbericht

nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations

In the Linux kernel, the following vulnerability has been resolved:

nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations

When fuzzing the nvme target code, I tripped a kernel warning in
nvmet_tcp_map_data() because the length passed into the allocator is
controlled by the remote initiator.

A remote initiator that sends a command with an SGL claiming a huge
number, can create a scatterlist and iovec allocation of over 1 million
entries, which causes the backing kmalloc call to exceed MAX_PAGE_ORDER
and then the page allocator will trip on a WARN_ON_ONCE_GFP() message:

  WARNING: mm/page_alloc.c:5280 __alloc_frozen_pages_noprof
  Workqueue: nvmet_tcp_wq nvmet_tcp_io_work
  ...
  sgl_alloc_order
  nvmet_tcp_map_data
  nvmet_tcp_try_recv_pdu

As it's never good to trip a kernel warning remotely due to many systems
having panic-on-warn enabled, let's silence it by just add GFP_NOWARN to
the allocation flags.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version < 8d01f0d0e96485e39ad89b859ef85e1dc3020465
Status affected
Version 872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version < 7b6a54d4e7b0da423c2b53ed293fd36b16c0b19e
Status affected
Version 872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version < e7077e6c45423dd2bb7de7b5fc4b018a8e6c4741
Status affected
Version 872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version < 86cc450022473c4a29b43a09f3ec22a9ef566dac
Status affected
Version 872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version < c509f20be1cabda3087810bb2d658d66b3f31f35
Status affected
Version 872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version < 9c95f7e66c62ee6c6abedcf1c04311f430ff5833
Status affected
Version 872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version < 7fd6da0f28932442b51658bac4ff55565ca9b377
Status affected
Version 872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version < 9b770e40bc00381e5ebf53653de5776773415be3
Status affected
Version 872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version < 737a3b535247226f6e1a7988fd9d6e63e7d6fc71
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.0
Status affected
Version 0
Version < 5.0
Status unaffected
Version <= 5.10.*
Version 5.10.267
Status unaffected
Version <= 5.15.*
Version 5.15.218
Status unaffected
Version <= 6.1.*
Version 6.1.185
Status unaffected
Version <= 6.6.*
Version 6.6.154
Status unaffected
Version <= 6.12.*
Version 6.12.106
Status unaffected
Version <= 6.18.*
Version 6.18.47
Status unaffected
Version <= 7.1.*
Version 7.1.11
Status unaffected
Version <= 7.2.*
Version 7.2.1
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.093
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/8d01f0d0e96485e39ad89b859ef85e1dc3020465
https://git.kernel.org/stable/c/7b6a54d4e7b0da423c2b53ed293fd36b16c0b19e
https://git.kernel.org/stable/c/e7077e6c45423dd2bb7de7b5fc4b018a8e6c4741
https://git.kernel.org/stable/c/86cc450022473c4a29b43a09f3ec22a9ef566dac
https://git.kernel.org/stable/c/c509f20be1cabda3087810bb2d658d66b3f31f35
https://git.kernel.org/stable/c/9c95f7e66c62ee6c6abedcf1c04311f430ff5833
https://git.kernel.org/stable/c/7fd6da0f28932442b51658bac4ff55565ca9b377
https://git.kernel.org/stable/c/9b770e40bc00381e5ebf53653de5776773415be3
https://git.kernel.org/stable/c/737a3b535247226f6e1a7988fd9d6e63e7d6fc71