Impact
The kernel’s nvme‑tcp implementation fails to verify that a received C2HData protocol data unit (PDU) corresponds to a read command. A controller that replies to a write command with C2HData triggers a kernel warning, which can be fatal when the system is configured to panic on warnings. The flaw does not corrupt memory but causes an emergency reset of the controller and a host crash.
Affected Systems
All Linux kernels that include the nvme‑tcp driver are affected until the patch is applied. No specific vendor or version subset is listed; the issue applies broadly to any Linux kernel using the nvme‑tcp subsystem.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity vulnerability. The EPSS score of less than 1% suggests exploit activity is currently low, and the vulnerability is not yet in the CISA KEV catalog. Exploitation requires an attacker able to send crafted NVMe over TCP messages to a target host, such as through a compromised or malicious NVMe controller. If successful, the attacker can force the host to panic and reset, resulting in a denial of service. Because the flaw is a missing validation check, there is no mode of remote code execution; the impact is limited to a deliberate crash of the host.
OpenCVE Enrichment
Debian DLA
Debian DSA