Description
In the Linux kernel, the following vulnerability has been resolved:

nvme-fabrics: fix DHCHAP secret leak on parse failure

nvmf_parse_options() duplicates dhchap_secret and dhchap_ctrl_secret
with match_strdup() before validating the DHHC-1: representation.

If validation fails, the parser returns -EINVAL before the temporary
string in p is assigned to opts->dhchap_secret or
opts->dhchap_ctrl_secret. nvmf_create_ctrl() subsequently frees opts,
but nvmf_free_options() cannot release the unassigned temporary string.
Each rejected option therefore leaks one allocation.

This is easy to miss because valid secrets transfer ownership to opts
and are freed normally, while the malformed-secret path still returns
the expected -EINVAL to userspace.

With CONFIG_NVME_HOST_AUTH enabled, the leak is reachable before the
required-option checks and transport lookup. No NVMe-oF target or
working transport connection is required; for example, repeatedly
writing

dhchap_secret=BAD

or

dhchap_ctrl_secret=BAD

to /dev/nvme-fabrics deterministically takes the leaking parse path.

Free the temporary string before leaving both validation error paths.
Use kfree_sensitive() because the copied option may contain secret
material even when its representation is rejected, matching the
sensitive cleanup used for stored DHCHAP secrets.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Exposure – Secret Leak
Action: Patch
AI Analysis

Impact

The Linux kernel parser for NVMe‑Fabrics options duplicates the DHCHAP secret strings before validating them. If validation fails, the parser returns an error before the duplicated data is assigned to the options structure, but the temporary string remains allocated. When the options structure is later freed, the unassigned temporary string is not released, causing a memory leak that contains the secret material. This flaw results in an information disclosure of sensitive credentials each time a malformed secret is provided. The primary weakness is the inadvertent leakage of secret data due to improper cleanup (CWE‑200).

Affected Systems

The vulnerability affects all Linux kernels that include the NVMe‑Fabrics host authentications, specifically with the CONFIG_NVME_HOST_AUTH option enabled. It does not require a running NVMe target or network connection; any system with the device node /dev/nvme-fabrics can exercise the flaw.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation probability at this time. The attack vector is local: an attacker with access to the host can repeatedly write malformed values such as "dhchap_secret=BAD" to /dev/nvme-fabrics, so the bypass requires only local privilege. The impact is confidential data leakage of DHCHAP secrets, with moderate ease of execution but limited scope to systems where host authentication is enabled.

Generated by OpenCVE AI on September 18, 2026 at 04:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch from the commits linked in the advisory
  • If immediate kernel upgrade is not feasible, consider disabling the CONFIG_NVME_HOST_AUTH kernel configuration to eliminate the vulnerable code path
  • Verify that the device node /dev/nvme-fabrics is not exposed to untrusted local users when the kernel is upgraded to remove the leak

Generated by OpenCVE AI on September 18, 2026 at 04:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-359

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nvme-fabrics: fix DHCHAP secret leak on parse failure nvmf_parse_options() duplicates dhchap_secret and dhchap_ctrl_secret with match_strdup() before validating the DHHC-1: representation. If validation fails, the parser returns -EINVAL before the temporary string in p is assigned to opts->dhchap_secret or opts->dhchap_ctrl_secret. nvmf_create_ctrl() subsequently frees opts, but nvmf_free_options() cannot release the unassigned temporary string. Each rejected option therefore leaks one allocation. This is easy to miss because valid secrets transfer ownership to opts and are freed normally, while the malformed-secret path still returns the expected -EINVAL to userspace. With CONFIG_NVME_HOST_AUTH enabled, the leak is reachable before the required-option checks and transport lookup. No NVMe-oF target or working transport connection is required; for example, repeatedly writing dhchap_secret=BAD or dhchap_ctrl_secret=BAD to /dev/nvme-fabrics deterministically takes the leaking parse path. Free the temporary string before leaving both validation error paths. Use kfree_sensitive() because the copied option may contain secret material even when its representation is rejected, matching the sensitive cleanup used for stored DHCHAP secrets.
Title nvme-fabrics: fix DHCHAP secret leak on parse failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:53.836Z

Reserved: 2026-09-11T19:38:34.779Z

Link: CVE-2026-89975

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:08.337

Modified: 2026-09-16T11:17:08.337

Link: CVE-2026-89975

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:12:37Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor