Impact
The Linux kernel parser for NVMe‑Fabrics options duplicates the DHCHAP secret strings before validating them. If validation fails, the parser returns an error before the duplicated data is assigned to the options structure, but the temporary string remains allocated. When the options structure is later freed, the unassigned temporary string is not released, causing a memory leak that contains the secret material. This flaw results in an information disclosure of sensitive credentials each time a malformed secret is provided. The primary weakness is the inadvertent leakage of secret data due to improper cleanup (CWE‑200).
Affected Systems
The vulnerability affects all Linux kernels that include the NVMe‑Fabrics host authentications, specifically with the CONFIG_NVME_HOST_AUTH option enabled. It does not require a running NVMe target or network connection; any system with the device node /dev/nvme-fabrics can exercise the flaw.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation probability at this time. The attack vector is local: an attacker with access to the host can repeatedly write malformed values such as "dhchap_secret=BAD" to /dev/nvme-fabrics, so the bypass requires only local privilege. The impact is confidential data leakage of DHCHAP secrets, with moderate ease of execution but limited scope to systems where host authentication is enabled.
OpenCVE Enrichment
Debian DLA
Debian DSA