Description
In the Linux kernel, the following vulnerability has been resolved:

nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers

Currently, when nvmet_tcp_build_pdu_iovec() detects an out-of-bounds
PDU length or offset, it triggers nvmet_tcp_fatal_error(cmd->queue)
and returns early. However, because the function returns void, the
callers are entirely unaware that a fatal error has occurred and
that the cmd->recv_msg.msg_iter was left uninitialized.

Callers such as nvmet_tcp_handle_h2c_data_pdu() proceed to blindly
overwrite the queue state with queue->rcv_state = NVMET_TCP_RECV_DATA
Consequently, the socket receiving loop may attempt to read incoming
network data into the uninitialized iterator.

Fix this by shifting the error handling responsibility to the callers.
Published: 2026-06-24
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the Linux kernel’s nvmet‑tcp subsystem. A helper function that builds a PDU iterator returns void and discards errors when it detects an out‑of‑bounds PDU length or offset. Because callers are not notified of the failure, they overwrite the command’s state and later use an uninitialized iterator to read network data. This improper error handling and the use of uninitialized memory could allow an attacker who injects crafted network packets to corrupt kernel memory and potentially achieve arbitrary code execution with kernel privileges. The CVE description indicates this risk, though it does not detail a confirmed exploitation case.

Affected Systems

The affected component is the Linux kernel, specifically the nvmet‑tcp implementation. No explicit version range is listed in the CNA data; therefore, any kernel that contains the vulnerable nvmet‑tcp code before the patch applies is potentially affected. The CNA vendor is Linux, and the product is the Linux kernel. The common platform enumeration strings include all kernel versions and the specific releases 6.19 and 7.1‑rc1, but versioned impact cannot be determined from the data.

Risk and Exploitability

The CVSS score of 9.8 reflects a critical severity, and the EPSS score of less than 1 % indicates a low probability of exploitation at the time of this analysis. The flaw can be triggered over the network by sending malformed nvmet‑tcp PDUs to a host that exposes the service. While the CVE notes a potential for kernel memory corruption and arbitrary code execution, it does not confirm that this is achieved in practice; therefore, the actual exploitability is inferred from the described mechanics. The flaw is not listed in the CISA KEV catalog. The most likely attack vector is network‑based, requiring the attacker to have access to the nvmet‑tcp port from an untrusted host.

Generated by OpenCVE AI on August 12, 2026 at 06:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that contains the nvmet‑tcp error‑handling fix; consult your distribution’s security advisories for the appropriate package version.
  • If an immediate kernel upgrade is not possible, disable the nvmet‑tcp protocol or configure it to bind only to trusted network interfaces so that untrusted hosts cannot send PDU data.
  • Implement network filtering or firewall rules to block or restrict access to the nvmet‑tcp port from external or potentially malicious hosts.

Generated by OpenCVE AI on August 12, 2026 at 06:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4665-1 linux security update
Debian DLA Debian DLA DLA-4671-1 linux-6.1 security update
Ubuntu USN Ubuntu USN USN-8566-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8567-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8568-1 Linux kernel (OEM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8569-1 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-8574-1 Linux kernel (GCP FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8593-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8574-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-1 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8596-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-2 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8603-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8606-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8607-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8608-1 Linux kernel (Azure FIPS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8609-1 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8574-3 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8595-3 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8618-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8619-1 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8636-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-2 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-3 Linux kernel (NVIDIA Tegra IGX) vulnerabilities
Ubuntu USN Ubuntu USN USN-8631-4 Linux kernel (Azure CVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8636-2 Linux kernel (Oracle) vulnerabilities
Ubuntu USN Ubuntu USN USN-8661-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8663-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8664-1 Linux kernel (NVIDIA BaseOS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8665-1 Linux kernel (Raspberry Pi) vulnerabilities
Ubuntu USN Ubuntu USN USN-8666-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8667-1 Linux kernel (KVM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8669-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8661-2 Linux kernel (Low Latency) vulnerabilities
History

Sun, 28 Jun 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665
CWE-682

Sun, 28 Jun 2026 08:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 26 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-390
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 24 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665
CWE-682

Wed, 24 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers Currently, when nvmet_tcp_build_pdu_iovec() detects an out-of-bounds PDU length or offset, it triggers nvmet_tcp_fatal_error(cmd->queue) and returns early. However, because the function returns void, the callers are entirely unaware that a fatal error has occurred and that the cmd->recv_msg.msg_iter was left uninitialized. Callers such as nvmet_tcp_handle_h2c_data_pdu() proceed to blindly overwrite the queue state with queue->rcv_state = NVMET_TCP_RECV_DATA Consequently, the socket receiving loop may attempt to read incoming network data into the uninitialized iterator. Fix this by shifting the error handling responsibility to the callers.
Title nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-24T12:07:11.778Z

Reserved: 2026-06-09T07:44:35.376Z

Link: CVE-2026-52989

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2026-06-24T17:17:09.707

Modified: 2026-08-21T13:18:17.153

Link: CVE-2026-52989

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-24T00:00:00Z

Links: CVE-2026-52989 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T06:45:04Z

Weaknesses
  • CWE-390

    Detection of Error Condition Without Action

  • CWE-908

    Use of Uninitialized Resource