-
CVE-2026-90412
- EPSS 0.19%
- Veröffentlicht 17.09.2026 16:09:38
- Zuletzt bearbeitet 17.09.2026 17:17:43
- Erkennungen
nvmet: fix return status of RMI log page on allocation failure
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix return status of RMI log page on allocation failure nvmet_execute_get_log_page_rmi() leaves 'status' holding NVME_SC_SUCCESS (set by the successful nvmet_req_find_ns() call) when the kzalloc() for the log buffer fails. It then jumps to the out label and completes the request with a success status, so the host is told the command succeeded while no data was transferred. Initialize 'status' to NVME_SC_INTERNAL, matching the smart log handler, so an allocation failure is reported as an internal error.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
5fd075cdaf3649000677d960fd9e45c08081b7e0
Version <
9e136150ac55df4b7ea36e6110ffa39d08905f37
Status
affected
Version
5fd075cdaf3649000677d960fd9e45c08081b7e0
Version <
581d8bb556dd3e5567bcf322aa5e3e4b6a200c08
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.13
Status
affected
Version
0
Version <
6.13
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.088 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/9e136150ac55df4b7ea36e6110ffa39d08905f37
https://git.kernel.org/stable/c/581d8bb556dd3e5567bcf322aa5e3e4b6a200c08