Executive brief
A vulnerability was identified in the Linux kernel's NVMe-over-TCP implementation, which is used for high-performance network storage. When data verification (digests) is enabled, a specific type of network error can cause the system to incorrectly release memory resources twice. This could lead to a system crash or potentially allow an attacker to disrupt storage services.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's nvmet-tcp driver. When data digest is enabled and a mismatch occurs on a non-final H2C_DATA PDU during an R2T-based transfer, the error handler `nvmet_tcp_try_recv_ddgst()` calls `nvmet_req_uninit()` without marking the command as completed. During subsequent queue teardown, `nvmet_tcp_uninit_data_in_cmds()` finds the command still active and calls `nvmet_req_uninit()` again, resulting in a double `percpu_ref_put()`. This can lead to premature memory reclamation and subsequent use-after-free. The issue is resolved by ensuring the command status is set to `NVME_SC_CMD_SEQ_ERROR` during the initial error handling.
Affected products
- Linux Linux Kernel 6.1.178, 6.6.145, 6.12.97, 6.18.40
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory
References
- https://git.kernel.org/stable/c/088ee46c18d99baef453afd74181dd40ade044ad
- https://git.kernel.org/stable/c/6f9442983a3e4227afd1c83a5251ddbca585ea21
- https://git.kernel.org/stable/c/96fe2513df590e74b04253a45089cae75569570e
- https://git.kernel.org/stable/c/dbbd07d0a7020b80f6a7028e561908f7b83b3d5a
- https://git.kernel.org/stable/c/e091ff83d962f9ed00d9bd70443676de9fe98bdc