Impact
In the Linux kernel’s nvme over TCP stack, the nvme_tcp_handle_r2t() function fails to verify that an R2T request refers to a write operation. A malicious NVMe controller can therefore send an R2T for a read command. The kernel’s nvme_tcp_setup_h2c_data_pdu() and nvme_tcp_try_send_data() functions will forward the contents of the requested read buffer back to the controller. Consequently, arbitrary kernel memory—including stale page data and pointers—is exposed to the controller, which is not logged and completes normally. The weakness corresponds to CWE‑201, representing a physical information disclosure due to a read of unintended data.
Affected Systems
All Linux kernel builds that include the default nvme over TCP module and have not been updated with the commit that adds the R2T direction check (no specific version data is available).
Risk and Exploitability
The CVSS base score of 7.5 signals high severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. The attack requires a malicious NVMe controller connected to the host’s NVMe/TCP interface; it exploits the lack of direction verification and can be performed without privileged credentials or visible logs, transmitting kernel memory back to the attacker’s controller.
OpenCVE Enrichment
Debian DSA