Description
In the Linux kernel, the following vulnerability has been resolved:

nvme-tcp: reject a read that transferred too few bytes

nvme_tcp_recv_data() completes a request once the current C2HData PDU
has been consumed. Nothing compares the total bytes received against
the length the command asked for: struct nvme_tcp_request has no
receive-side counter, queue->data_remaining is per queue, and
blk_mq_end_request() completes for blk_rq_bytes(rq) unconditionally
with no residual concept anywhere above.

A controller can therefore answer a 4096-byte read with 512 bytes and
have it reported as a complete read; user space then gets 4096 bytes of
which 3584 are whatever was already in the page. I reproduced that with
a test target.

Count the bytes received and refuse to complete a successful read whose
count does not match, at the two NVME_TCP_F_DATA_SUCCESS paths and in
nvme_tcp_process_nvme_cqe(). The success test shifts req->status right
by one, because the driver keeps the wire value there and shifts it on
completion, so the check must see what the completion path will see.
Only REQ_OP_READ is checked, because there the length comes from the
sectors the request covers; a passthrough command is built by its
submitter, which picks both command and buffer, so the kernel has
nothing to compare against.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The Linux kernel’s nvme_tcp driver fails to compare the total number of bytes received against what the command requested, marking a read as complete without verifying that the payload length matches. A controller can therefore respond to a 4096‑byte read with only 512 bytes and the kernel will still report success. User space then receives a full 4096‑byte buffer, with the missing 3584 bytes being whatever was already present on the page, potentially exposing sensitive or stale data. The flaw is a classic case of MissingByteCount, captured by CWE‑130, and can lead to information disclosure.

Affected Systems

All Linux kernel releases that include the nvme_tcp driver and are older than the commit that added the byte‑count verification are affected. This includes every supported distribution kernel that ships the nvme_tcp module without the upstream patch. Users should consult vendor release notes to determine whether their kernel version contains the fix.

Risk and Exploitability

The CVSS score of 7.5 categorizes this as a moderate‑to‑score indicates a very low probability of exploitation (<1%). The vulnerability is not listed in CISA KEV, implying no widely reported or active exploitation. Attackers would need the ability to influence or control the NVMe controller to force truncated responses, which could be achieved with a compromised or malicious controller or through network‑based manipulation of NVMe‑TCP traffic. The impact manifests primarily as information disclosure rather than denial of service or code execution.

Generated by OpenCVE AI on September 15, 2026 at 22:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the upstream commit validating read byte counts, or apply the patch directly to the current source tree, ensuring the kernel recompiles and loads the corrected nvme_tcp module.
  • If an upgrade is not feasible, disable NVMe‑TCP support by unloading the nvme_tcp kernel module with `modprobe -r nvme_tcp` or preventing its insertion with a blacklist entry, thereby preventing the vulnerable read path from being exercised.
  • Enforce strict device‑level access controls, such as SELinux or device isolation mechanisms, to restrict untrusted NVMe controllers from communicating with the system and mitigate the risk of an attacker sending malformed responses.

Generated by OpenCVE AI on September 15, 2026 at 22:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-130
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: reject a read that transferred too few bytes nvme_tcp_recv_data() completes a request once the current C2HData PDU has been consumed. Nothing compares the total bytes received against the length the command asked for: struct nvme_tcp_request has no receive-side counter, queue->data_remaining is per queue, and blk_mq_end_request() completes for blk_rq_bytes(rq) unconditionally with no residual concept anywhere above. A controller can therefore answer a 4096-byte read with 512 bytes and have it reported as a complete read; user space then gets 4096 bytes of which 3584 are whatever was already in the page. I reproduced that with a test target. Count the bytes received and refuse to complete a successful read whose count does not match, at the two NVME_TCP_F_DATA_SUCCESS paths and in nvme_tcp_process_nvme_cqe(). The success test shifts req->status right by one, because the driver keeps the wire value there and shifts it on completion, so the check must see what the completion path will see. Only REQ_OP_READ is checked, because there the length comes from the sectors the request covers; a passthrough command is built by its submitter, which picks both command and buffer, so the kernel has nothing to compare against.
Title nvme-tcp: reject a read that transferred too few bytes
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:17.079Z

Reserved: 2026-09-11T19:38:34.711Z

Link: CVE-2026-89480

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:29.470

Modified: 2026-09-14T13:19:04.623

Link: CVE-2026-89480

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:35Z

Links: CVE-2026-89480 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:00:16Z

Weaknesses
  • CWE-130

    Improper Handling of Length Parameter Inconsistency