Impact
A NULL pointer dereference occurs in the Linux kernel NVMe target driver when a host issues an Identify command with CNS 05h and CSI 02h to a file‑backed namespace. The function nvmet_execute_identify_ns_zns calls bdev_is_zoned() on req->ns->bdev; for a file‑backed namespace this pointer is NULL, causing a kernel crash. The crash represents a denial‑of‑service event because the kernel panics when the faulty path is exercised. This flaw is a classic Null Pointer Dereference vulnerability (CWE‑476).
Affected Systems
The flaw affects the Linux kernel in any build that enables NVMe target support and the CONFIG_BLK_DEV_ZONED option. All versions of the kernel that include a file‑backed namespace and this option are potentially vulnerable. No specific kernel release is listed in the data, so any kernel with these features prior to the applied patch is at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS probability is less than 1 %, implying a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based through an NVMe target, as the flaw is triggered when a host sends an Identify command with specific parameters. Based on the description, it is inferred that no special authentication or privilege escalation is required beyond simply having connectivity to the NVMe service. The crash occurs in kernel code and would result in a system interruption, not remote code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA