9.8
CVE-2026-89969
- EPSS 0.7%
- Veröffentlicht 16.09.2026 10:32:49
- Zuletzt bearbeitet 16.09.2026 15:18:21
- Erkennungen
nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU nvmet_tcp_try_recv_pdu() reads a PDU header into the fixed 128-byte queue->pdu union, then computes the remaining payload length as queue->left = hdr->hlen - queue->offset + hdgst; and reads that many more bytes into &queue->pdu + queue->offset, without ever bounding the result against sizeof(queue->pdu). A struct nvme_tcp_icreq_pdu is itself 128 bytes, exactly the size of the union. Once a header digest has been negotiated (hdgst = 4), a second ICReq passes the hlen == nvmet_tcp_pdu_size() check but yields queue->left = 128 - 8 + 4 = 124, so bytes 8..132 are written into the 128-byte buffer -- 4 bytes past its end, over queue->hdr_digest and queue->data_digest. Those bytes are attacker-controlled (an ICReq carries no digest), and the duplicate ICReq is only rejected later, after the overflow. A remote unauthenticated host can thus corrupt kernel memory adjacent to the receive buffer. Reject any PDU whose declared length would read past the end of queue->pdu before the second recv.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version <
a3f0bcfbaf3312a5754d1ce020a07d394669eb25
Status
affected
Version
872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version <
4f84d42c53c49557fb1ef285c683b0a81b576c74
Status
affected
Version
872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version <
58dc6035b79c4c73c0cbf9ec9f68a7f117b2b3e6
Status
affected
Version
872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version <
cf5f39d2b58f97e0cd1829c4a6aeef17f1607cca
Status
affected
Version
872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version <
3a385e0c39efbe34db8edd95900c123113ae3450
Status
affected
Version
872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version <
dbc4acbdb3ca8c81441368ad7409b8f77d4de8f6
Status
affected
Version
872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version <
d95d342bc0ea82dc79e6362b2f1f997431750e4c
Status
affected
Version
872d26a391da92ed8f0c0f5cb5fef428067b7f30
Version <
14cc5a7e77731497d5bea70f3bb05df7eda982e4
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.0
Status
affected
Version
0
Version <
5.0
Status
unaffected
Version <=
5.10.*
Version
5.10.270
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.51
Status
unaffected
Version <=
7.2.*
Version
7.2.5
Status
unaffected
Version <=
*
Version
7.3-rc2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.7% | 0.515 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/a3f0bcfbaf3312a5754d1ce020a07d394669eb25
https://git.kernel.org/stable/c/4f84d42c53c49557fb1ef285c683b0a81b576c74
https://git.kernel.org/stable/c/58dc6035b79c4c73c0cbf9ec9f68a7f117b2b3e6
https://git.kernel.org/stable/c/cf5f39d2b58f97e0cd1829c4a6aeef17f1607cca
https://git.kernel.org/stable/c/3a385e0c39efbe34db8edd95900c123113ae3450
https://git.kernel.org/stable/c/dbc4acbdb3ca8c81441368ad7409b8f77d4de8f6
https://git.kernel.org/stable/c/d95d342bc0ea82dc79e6362b2f1f997431750e4c
https://git.kernel.org/stable/c/14cc5a7e77731497d5bea70f3bb05df7eda982e4