Junglewise Threat Intelligence

CVE-2026-46105: Linux Kernel kernel oops in mpt3sas driver via oversized NVMe I/O

CVE-2026-46105 · Severity: info · CVSS 5.5 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's storage driver for Broadcom/LSI SAS controllers could allow a local user to crash the system. The issue occurs when the system attempts to perform large data transfers to NVMe drives that exceed the driver's internal memory limits. This results in a 'kernel oops' (system crash), which can disrupt operations and lead to a denial of service.

Technical details

The vulnerability exists in the mpt3sas SCSI driver within the Linux kernel. The driver allocates a fixed 4K buffer for the Physical Region Page (PRP) list, which can accommodate a maximum of 512 entries, effectively limiting I/O transfers to 2 MiB. However, the driver previously relied on the Maximum Data Transfer Size (MDTS) reported by the HBA firmware, which could exceed this 2 MiB limit. When an I/O request larger than 2 MiB is issued, it leads to a kernel oops. The fix involves capping the 'max_hw_sectors' to the smaller of the reported MDTS or the 2 MiB driver limit. This is primarily a local denial-of-service vector.

Affected products

  • Linux Linux Kernel All versions prior to the fix in mpt3sas driver

Timeline

  • 2026-04-14: other: Patch authored by Broadcom
  • 2026-05-28: disclosed: CVE published
  • 2026-05-28: patched: Fixes merged into stable kernel branches

References