Impact
The vulnerability allows a remote host to send a data packet (H2CData PDU) before the target has issued a corresponding request for data (R2T). Because the kernel code accepts the packet without verifying that it is expected, it records the command twice in a response queue. The duplicated list node generates a loop that never exits, causing the NVMe target workqueue to block and the system to experience a soft‑lockup. The flaw does not require any authentication when the subsystem permits any host, so any network attacker can trigger it by simply sending crafted packets over TCP. The result is a denial of service that can render a Linux machine unresponsive until it is rebooted.
Affected Systems
This flaw exists in the Linux kernel's NVMe over Fabrics TCP transport. All versions before the patch that includes the check in nvmet_tcp_handle_h2c_data_pdu() are affected. No vendor‑specific product names are listed; the issue is tied to the core Linux kernel implementation.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, and the EPSS score of less than 1% suggests a low probability of exploitation at the moment. The vulnerability is not currently listed in CISA’s KEV catalog. Attackers can exploit it remotely by sending out‑of‑order data packets to an open NVMe over Fabrics port, and no special privileges or authentication are needed on a system that allows any host. If a provider applies the patch, the risk is mitigated; otherwise, the system remains vulnerable to a soft‑lockup that could disrupt services.
OpenCVE Enrichment
Debian DLA
Debian DSA