Impact
In the Linux kernel, the NVME_IOCTL_SUBMIT_IO ioctl lacks a call to nvme_cmd_allowed(), allowing an unprivileged user to issue arbitrary I/O commands on an NVMe partition device, including writing through a file descriptor that is intended to be read-only. The flaw enables unauthorized writes and can be leveraged for privilege escalation or data corruption. The weakness is an unauthorized access control flaw.
Affected Systems
All versions of the Linux kernel that expose the NVMe ioctl interface are affected until the patch that adds the proper permission check is applied. No specific kernel release is listed but the change applies to any kernel where the check is missing.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker must have access to an NVMe device and the ability to issue the ioctl call, which is currently unconstrained. Despite a straightforward exploitation path, the overall risk is moderate due to the low exploitation likelihood, but the impact warrants immediate patching.
OpenCVE Enrichment
Debian DLA
Debian DSA