8.2
CVE-2026-89973
- EPSS 0.61%
- Veröffentlicht 16.09.2026 10:32:52
- Zuletzt bearbeitet 16.09.2026 15:18:21
- Erkennungen
nvme-tcp: check the data direction of a C2HData PDU
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: check the data direction of a C2HData PDU nvme_tcp_handle_c2h_data() finds the request by command id and checks that it has a payload, but it does not check that the command asked for data to be read. A controller that answers a write command with C2HData therefore reaches nvme_tcp_recv_data(), where _copy_to_iter() hits WARN_ON_ONCE(i->data_source) and returns 0. The receive path turns that into -EFAULT and resets the controller. No data is copied, so this is not memory corruption. What a controller gets is a kernel warning it can raise at will, which is fatal on a host booted with panic_on_warn. The send path already knows the direction - it consults rq_data_dir() when it builds a command - and nvme_tcp_handle_r2t() checks the length and the offset of the request it names. The C2HData path does not check the direction at all. Reject a C2HData PDU whose command is not a read. Rejecting it fails the command and resets the controller, as the neighbouring check in this function does; what goes away is the warning. [ 6.885580] ------------[ cut here ]------------ [ 6.886457] WARNING: lib/iov_iter.c:193 at _copy_to_iter+0x289/0x1330, CPU#0: kworker/0:1H/71 [ 6.888137] CPU: 0 UID: 0 PID: 71 Comm: kworker/0:1H Not tainted 7.2.0-rc5-NVMETCP-gf5098b6bae76 #1 PREEMPT(lazy) [ 6.891165] Workqueue: nvme_tcp_wq nvme_tcp_io_work [ 6.891875] RIP: 0010:_copy_to_iter+0x289/0x1330 [ 6.903739] Call Trace: [ 6.904085] <TASK> [ 6.909254] __skb_datagram_iter+0x433/0x820 [ 6.911026] skb_copy_datagram_iter+0x37/0x120 [ 6.911622] nvme_tcp_recv_skb+0xa07/0x4320 [ 6.913378] __tcp_read_sock+0x1ab/0x810 [ 6.915788] nvme_tcp_try_recv+0x152/0x1e0 [ 6.918222] nvme_tcp_io_work+0x1e4/0x6c0 [ 6.926906] </TASK> [ 6.927226] ---[ end trace 0000000000000000 ]--- [ 6.927878] nvme nvme0: queue 1 failed to copy request 0x71 data [ 6.928709] nvme nvme0: receive failed: -14
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
3f2304f8c6d6ed97849057bd16fee99e434ca796
Version <
df74950ba6008655d4a977d17df7faf4b6e52b74
Status
affected
Version
3f2304f8c6d6ed97849057bd16fee99e434ca796
Version <
980d990f3c0560d7dfbfbf14699651fdf02f26ee
Status
affected
Version
3f2304f8c6d6ed97849057bd16fee99e434ca796
Version <
5b115d932f6e769ac80783fb18edd21b0aed256e
Status
affected
Version
3f2304f8c6d6ed97849057bd16fee99e434ca796
Version <
0673a2affe45ca76b60de31a83c67b1e60f81bde
Status
affected
Version
3f2304f8c6d6ed97849057bd16fee99e434ca796
Version <
80d56202fbdff8906be6954b2776e5c14a4026f2
Status
affected
Version
3f2304f8c6d6ed97849057bd16fee99e434ca796
Version <
b4af7999a998787d5eb6facb5a333e04a4f1d2d9
Status
affected
Version
3f2304f8c6d6ed97849057bd16fee99e434ca796
Version <
a0c389b8a495bda1eb719d2503853c924b7a8355
Status
affected
Version
3f2304f8c6d6ed97849057bd16fee99e434ca796
Version <
f83af377c148f6ad94b41c0e8313f12adf45e1c1
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.0
Status
affected
Version
0
Version <
5.0
Status
unaffected
Version <=
5.10.*
Version
5.10.270
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.51
Status
unaffected
Version <=
7.2.*
Version
7.2.5
Status
unaffected
Version <=
*
Version
7.3-rc2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.61% | 0.476 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.2 | 3.9 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
|
https://git.kernel.org/stable/c/df74950ba6008655d4a977d17df7faf4b6e52b74
https://git.kernel.org/stable/c/980d990f3c0560d7dfbfbf14699651fdf02f26ee
https://git.kernel.org/stable/c/5b115d932f6e769ac80783fb18edd21b0aed256e
https://git.kernel.org/stable/c/0673a2affe45ca76b60de31a83c67b1e60f81bde
https://git.kernel.org/stable/c/80d56202fbdff8906be6954b2776e5c14a4026f2
https://git.kernel.org/stable/c/b4af7999a998787d5eb6facb5a333e04a4f1d2d9
https://git.kernel.org/stable/c/a0c389b8a495bda1eb719d2503853c924b7a8355
https://git.kernel.org/stable/c/f83af377c148f6ad94b41c0e8313f12adf45e1c1