Executive brief
The Linux kernel's NVMe over TCP driver has a memory corruption vulnerability where improper validation of incoming C2HData (controller-to-host data) frames can cause data to be written to uninitialized or stale memory locations. An attacker with network access to an NVMe target can trigger a kernel crash (denial of service) or potentially execute arbitrary code by crafting malicious NVMe commands.
Technical details
The vulnerability is a wild memory access (CWE-415) in the nvme-tcp receive handler. The root cause is that the receive-side validation of C2HData frames relies only on blk_rq_payload_bytes() without checking req->data_len, which mirrors an earlier fix to nvme_tcp_setup_cmd_pdu(). For REQ_OP_WRITE_ZEROES commands (which have no physical segments but non-zero payload bytes), this allows a C2HData frame to pass validation even when req->iter is uninitialized from a previous command on the same NVMe tag. The driver then copies the received data into this stale iterator, causing a write to wild memory addresses. The vulnerability is network-accessible and requires no authentication, as it occurs during the NVMe protocol handshake/command processing phase. The fix adds req->data_len to the validation gate, ensuring both the old test (blk_rq_payload_bytes) and the new safeguard are checked before accepting data.
Affected products
- Linux Linux kernel < 7.2.0-rc5 (fixed in commit f5098b6bae76)
Timeline
- 2026-09-11: disclosed
- 2026-09-11: patched