Executive brief
The Linux kernel's NVMe storage driver has a flaw where the fallback discard page buffer is not properly initialized, potentially leaking uninitialized kernel memory to storage devices. When the normal memory allocation fails under pressure, stale data from the page (including kernel pointers) is sent to the controller, which could expose sensitive kernel information.
Technical details
The vulnerability is an information disclosure flaw in the NVMe subsystem's discard handling code (nvme_setup_discard()). The nvme_init_ctrl() function allocates a per-controller fallback discard page using alloc_page(GFP_KERNEL) without zeroing it. Under memory pressure, when the primary kzalloc(GFP_ATOMIC | __GFP_NOWARN) allocation fails, the uninitialized fallback page is used directly as the DSM payload, allowing up to 4080 bytes of stale kernel memory (including struct page pointers) to be sent to the NVMe device. Triggering this requires memory pressure conditions; it is not remotely exploitable but could leak sensitive kernel address information. The fix allocates the fallback page with __GFP_ZERO to ensure it is always zeroed.
Affected products
- Linux Linux kernel before fix (CVE-2026-89483)
Timeline
- 2026-09-11: disclosed