9.1

CVE-2026-90230

nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()

In the Linux kernel, the following vulnerability has been resolved:

nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()

nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with
the host-supplied transfer length (tl) and hands it to
nvmet_auth_negotiate() without passing tl along. nvmet_auth_negotiate()
then reads the negotiate header and, for each of the halen hash
identifiers and dhlen DH group identifiers, indexes into the fixed
idlist[60] array (hashes at idlist[0..halen), groups at idlist[30..]).

Neither the transfer length nor halen/dhlen is validated. A malicious or
non-conformant host can report a tl smaller than the negotiate structure,
or a halen/dhlen larger than the array (both are u8, up to 255), making
the loops read past the end of the allocated buffer (heap out-of-bounds
read). The sibling nvmet_auth_reply() already validates tl against the
structure size; the negotiate path did not.

Pass tl into nvmet_auth_negotiate(), reject a tl that does not cover the
negotiate data plus one full protocol descriptor, and reject halen/dhlen
larger than NVME_AUTH_DHCHAP_MAX_DH_IDS.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < 89ff11b72f38976f3b5aea23a5228ee05e277209
Status affected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < aaac783950b17c57df9b6f7344747cacb1a407ed
Status affected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < c38a8186326799957d293d370136c128cd113916
Status affected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < 7b81e4d2230e3d2d372c826180c4ef0efc244f31
Status affected
Version db1312dd95488b5e6ff362ff66fcf953a46b1821
Version < 5bb96cc218835769ab74ec7f3ea2bf81fbffe955
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.0
Status affected
Version 0
Version < 6.0
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.39
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/89ff11b72f38976f3b5aea23a5228ee05e277209
https://git.kernel.org/stable/c/aaac783950b17c57df9b6f7344747cacb1a407ed
https://git.kernel.org/stable/c/c38a8186326799957d293d370136c128cd113916
https://git.kernel.org/stable/c/7b81e4d2230e3d2d372c826180c4ef0efc244f31
https://git.kernel.org/stable/c/5bb96cc218835769ab74ec7f3ea2bf81fbffe955