Impact
The Linux kernel’s nvme_tcp driver fails to compare the total number of bytes received against what the command requested, marking a read as complete without verifying that the payload length matches. A controller can therefore respond to a 4096‑byte read with only 512 bytes and the kernel will still report success. User space then receives a full 4096‑byte buffer, with the missing 3584 bytes being whatever was already present on the page, potentially exposing sensitive or stale data. The flaw is a classic case of MissingByteCount, captured by CWE‑130, and can lead to information disclosure.
Affected Systems
All Linux kernel releases that include the nvme_tcp driver and are older than the commit that added the byte‑count verification are affected. This includes every supported distribution kernel that ships the nvme_tcp module without the upstream patch. Users should consult vendor release notes to determine whether their kernel version contains the fix.
Risk and Exploitability
The CVSS score of 7.5 categorizes this as a moderate‑to‑score indicates a very low probability of exploitation (<1%). The vulnerability is not listed in CISA KEV, implying no widely reported or active exploitation. Attackers would need the ability to influence or control the NVMe controller to force truncated responses, which could be achieved with a compromised or malicious controller or through network‑based manipulation of NVMe‑TCP traffic. The impact manifests primarily as information disclosure rather than denial of service or code execution.
OpenCVE Enrichment
Debian DSA