Junglewise Threat Intelligence

CVE-2026-23112: Linux Kernel out-of-bounds write in nvmet-tcp

CVE-2026-23112 · Severity: critical · CVSS 9.8 · Published 2026-02-13

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's NVMe over TCP implementation, which is used for high-speed data storage networking. An attacker could exploit this flaw to cause a system crash or potentially gain unauthorized access to data. This could lead to significant service outages or the exposure of sensitive information stored on affected systems.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the nvmet_tcp_build_pdu_iovec() function within the Linux kernel's NVMe over TCP target driver. The root cause is a failure to validate scatterlist (sg) boundaries when a PDU length or offset exceeds the scatterlist count (sg_cnt). This allows the function to walk past the intended memory buffer and use bogus length or offset values, resulting in a General Protection Fault (GPF) or KASAN detection during _copy_to_iter() operations. An unauthenticated remote attacker can trigger this via network-reachable NVMe-oF TCP services. Patches have been released across multiple stable kernel branches to add the necessary guards for sg_idx and sg_remaining entries.

Affected products

  • Linux Linux Kernel 5.0 to 5.10.250, 5.11 to 5.15.200, 5.16 to 6.1.163, 6.2 to 6.6.124, 6.7 to 6.12.70, 6.13 to 6.18.10, 6.19-rc1 to 6.19-rc8

Timeline

  • 2026-02-13: disclosed: Initial publication of the vulnerability advisory.
  • 2026-02-13: advisory: NVD published the CVE record.
  • 2026-04-18: patched: Fix for regression in stable backports committed to the stable tree.

References