Impact
The Linux kernel contains a race condition in the NVMe‑over‑TCP driver. A user process can change the subsystem maximum queue ID value while a controller is being allocated, causing the allocation to use a smaller buffer than the new limit. This triggers a KASAN out‑of‑bounds warning and can lead to memory corruption in kernel space. Because the corruption occurs in privileged kernel memory, it can be leveraged to gain additional privileges or crash the system. The weakness is a classic race condition that corrupts shared state.
Affected Systems
All Linux kernel builds that include the nvmet subsystem are potentially affected. No specific kernel versions are listed, so any kernel with the vulnerable driver code may be impacted. The vulnerability was identified from Linux kernel source changes and documented by the Linux CNA.
Risk and Exploitability
The EPSS score is below 1%, indicating a low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. However, the attack requires only local access that can modify configfs entries, which is often achievable by a user with write access to the NVMe configuration filesystem. Once the race is triggered, the kernel memory corruption can lead to privilege escalation or denial of service. The vulnerability does not appear to be exploitable remotely without local interference. Risk is moderate due to the potential impact but low exploitation likelihood.
OpenCVE Enrichment