Executive brief
A vulnerability exists in the Linux kernel's NVMe over TCP implementation, which is used for high-speed data storage networking. An attacker could exploit this flaw to cause a system crash or potentially gain unauthorized access to data. This could lead to significant service outages or the exposure of sensitive information stored on affected systems.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the nvmet_tcp_build_pdu_iovec() function within the Linux kernel's NVMe over TCP target driver. The root cause is a failure to validate scatterlist (sg) boundaries when a PDU length or offset exceeds the scatterlist count (sg_cnt). This allows the function to walk past the intended memory buffer and use bogus length or offset values, resulting in a General Protection Fault (GPF) or KASAN detection during _copy_to_iter() operations. An unauthenticated remote attacker can trigger this via network-reachable NVMe-oF TCP services. Patches have been released across multiple stable kernel branches to add the necessary guards for sg_idx and sg_remaining entries.
Affected products
- Linux Linux Kernel 5.0 to 5.10.250, 5.11 to 5.15.200, 5.16 to 6.1.163, 6.2 to 6.6.124, 6.7 to 6.12.70, 6.13 to 6.18.10, 6.19-rc1 to 6.19-rc8
Timeline
- 2026-02-13: disclosed: Initial publication of the vulnerability advisory.
- 2026-02-13: advisory: NVD published the CVE record.
- 2026-04-18: patched: Fix for regression in stable backports committed to the stable tree.
References
- https://git.kernel.org/stable/c/0b9981751be14b59b4473383c731c833738aebdb
- https://git.kernel.org/stable/c/1385be357e8acd09b36e026567f3a9d5c61139de
- https://git.kernel.org/stable/c/19672ae68d52ff75347ebe2420dde1b07adca09f
- https://git.kernel.org/stable/c/42afe8ed8ad2de9c19457156244ef3e1eca94b5d
- https://git.kernel.org/stable/c/52a0a98549344ca20ad81a4176d68d28e3c05a5c
- https://git.kernel.org/stable/c/ab200d71553bdcf4de554a5985b05b2dd606bc57
- https://git.kernel.org/stable/c/dca1a6ba0da9f472ef040525fab10fd9956db59f