Junglewise Threat Intelligence

CVE-2026-72130: Linux kernel nvmet-auth heap out-of-bounds write

CVE-2026-72130 · Severity: critical · CVSS 9.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NVMe-oF (NVMe over Fabrics) target implementation contains a heap buffer overflow in its in-band authentication handler. A remote attacker with network access to an NVMe-oF target using DH-HMAC-CHAP authentication can craft a malicious AUTH_RECEIVE command with an undersized buffer, causing the kernel to write past the allocated heap memory. This can lead to kernel crashes, memory corruption, and potential code execution on affected storage systems.

Technical details

The vulnerability is a heap out-of-bounds write in the nvmet-auth subsystem, specifically in the AUTH_RECEIVE command handling (nvmet_execute_auth_receive()). The root cause is insufficient validation of the allocation length parameter; the kernel only checks that it is nonzero and matches the transfer length, but does not verify it is large enough for the fixed-size DH-HMAC-CHAP response headers. When handling SUCCESS1 or FAILURE1 authentication states, the nvmet_auth_success1() and nvmet_auth_failure1() builders write fixed-size responses (16+ bytes depending on HMAC hash length) into the caller-supplied buffer without checking bounds. An unauthenticated remote NVMe-oF initiator can trigger a 16-byte heap write overflow by sending an AUTH_RECEIVE command with a one-byte allocation length. The fix validates the minimum required buffer length before allocation and rejects undersized requests. This is only exploitable on targets with in-band DH-HMAC-CHAP authentication enabled.

Affected products

  • Linux Linux kernel kernels with nvmet-auth (introduced by commit db1312dd9548, affected through at least 6.x before fix 779575bc35c687697ba69e904f2cd22e60112534)

Timeline

  • 2026-08-15: disclosed: CVE-2026-72130 published
  • 2026-06-10: patched: Upstream fix merged (commit 779575bc35c687697ba69e904f2cd22e60112534)
  • 2026-07-24: patched: Fix backported to stable kernels (commit 2eaa3ad450141cfcf187bb43cb8335eb336b5f87)

References

Related threats