Impact
Based on the description, it is inferred that the Linux kernel nvme-tcp subsystem can process a crafted C2HData packet that requests a WRITE_ZEROES operation while a residual iterator from a previous request remains on the same tag. Because the kernel reads the payload size without verifying the physical segment count, it copies the data into memory that no longer belongs to the current request, triggering a wild memory access that kills the kernel. The resulting crash provides a remote denial of service since an attacker can send the malformed NVMe-over-TCP frame from outside the host.
Affected Systems
All Linux kernel builds that include the nvme-tcp subsystem and have not yet incorporated the commit 25e5cb780e62, which implements a check of req->data_len to that commit. Distribution kernel packages built before the fix are therefore affected.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is network-based, using NVMe-over-TCP frames sent over TCP sockets. With a CVSS score of 9.8 the defect is critical, yet its EPSS score is under 1%, suggesting a low probability of exploitation in the wild. An attacker who can reach the target on the NVMe-over-TCP interface can cause a kernel panic, resulting in a denial of service. The issue is not listed in the CISA KEV catalog, so no public exploitation reports exist at this time.
OpenCVE Enrichment
Debian DSA