Impact
A remote unauthenticated host can send a crafted NVMe‑over‑TCP PDU that contains an over‑long header, causing the nvmet_tcp_try_recv_pdu() function to write beyond the bounds of a fixed 128‑byte buffer. The overflow corrupts adjacent kernel memory, giving an attacker control over kernel data structures and enabling privilege escalation or denial of service. The vulnerability arises from an unchecked calculation of the payload length during packet reception and leaves the buffer unbounded.
Affected Systems
Affected systems are Linux kernels that implement the nvmet_tcp driver; the specific distributions are not listed in the CVE data, but typical distributions that ship this driver are likely affected. Devices exposing the NVMe‑over‑TCP service (commonly port 4420) are directly susceptible.
Risk and Exploitability
With a CVSS score of 9.8, this vulnerability is classified as critical. The EPSS score is below 1%, implying a low probability of observed exploitation, but the vulnerability is not listed in the CISA KEV catalog. Attackers can remotely exploit this flaw by simply sending a crafted NVMe‑over‑TCP packet to an open port (usually 4420) without any authentication or privileged access. The lack of input bounds checking allows an over‑long PDU to overflow a 128-byte buffer, corrupt adjacent kernel memory, and potentially lead to arbitrary code execution or denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA