Impact
nvme_query_zone_info() incorrectly treats a successful NVMe status return as a failure, allowing the driver to continue with uninitialized zone data. This flaw propagates a zero zone size into the kernel’s block layer, leading to shift‑out‑of‑bounds errors and an UBSAN abort. The resulting kernel crash or silent failure can cause data loss and service interruption for storage devices that expose incorrect NVMe command responses, potentially enabling an attacker to provoke a denial of service by presenting a malfunctioning NVMe target or firmware. The weakness is an instance of improper input validation.
Affected Systems
Any Linux kernel built with the nvme block driver is affected, regardless of distribution, as the issue resides in the core nvme driver code. The vulnerability applies to NVMe devices, including local adapters and NVMe-over-Fabric targets, that return anomalous status codes for Identify Namespace or Identify Controller commands.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity risk, but the EPSS score of less than 1% suggests a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog, and no common exploitation tools are currently public. An attacker would need the ability to induce a device or firmware to return a positive status while failing the Identify actions, which might be achievable by subverting the firmware or by targeting a compromised NVMe‑oF service. The most likely attack vector involves remote or local privileged access to the storage subsystem where the attacker can trigger the malformed NVMe responses.
OpenCVE Enrichment