-

CVE-2026-80791

Medienbericht

nvmet-auth: zero the AUTH_RECEIVE response buffer

In the Linux kernel, the following vulnerability has been resolved:

nvmet-auth: zero the AUTH_RECEIVE response buffer

nvmet_execute_auth_receive() allocates the response buffer with kmalloc()
sized by the host-supplied AUTH_RECEIVE allocation length, but the
DH-HMAC-CHAP builders write only a fixed-size message into it. The full
allocation length is then copied to the wire by nvmet_copy_to_sgl(), so a
remote initiator receives the bytes past the built message -- up to nearly
a page of uninitialized slab -- during the pre-authentication handshake.

Allocate the buffer with kzalloc() so the unwritten tail is zeroed before
it is sent; conforming responses are unaffected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < 447b668faa14710f611e714031e3739ac3ec3a4f
Status affected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < 8f6363c8d54dde95982f0ab45e77cf57ec0efd62
Status affected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < dfcf013f77709ebdb282767edc2795a37cab5b57
Status affected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < b26189d28442183a8b5edb754f4a6918f77ca84e
Status affected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < 2dcc9226203da7275a9c29d20007da278d73d5e9
Status affected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < 1d6837d98bf966a041af65de5f78de7409ff83bc
Status affected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < 3ddcfb013322aa37eaa7a0d344b73079c38dfa21
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.0
Status affected
Version 0
Version < 6.0
Status unaffected
Version <= 6.1.*
Version 6.1.185
Status unaffected
Version <= 6.6.*
Version 6.6.154
Status unaffected
Version <= 6.12.*
Version 6.12.106
Status unaffected
Version <= 6.18.*
Version 6.18.47
Status unaffected
Version <= 7.1.*
Version 7.1.11
Status unaffected
Version <= 7.2.*
Version 7.2.1
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.108
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/447b668faa14710f611e714031e3739ac3ec3a4f
https://git.kernel.org/stable/c/8f6363c8d54dde95982f0ab45e77cf57ec0efd62
https://git.kernel.org/stable/c/dfcf013f77709ebdb282767edc2795a37cab5b57
https://git.kernel.org/stable/c/b26189d28442183a8b5edb754f4a6918f77ca84e
https://git.kernel.org/stable/c/2dcc9226203da7275a9c29d20007da278d73d5e9
https://git.kernel.org/stable/c/1d6837d98bf966a041af65de5f78de7409ff83bc
https://git.kernel.org/stable/c/3ddcfb013322aa37eaa7a0d344b73079c38dfa21