Description
In the Linux kernel, the following vulnerability has been resolved:

nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns()

When a host issues an Identify command with CNS 05h (I/O Command Set
specific Identify Namespace) and CSI 02h (ZNS) targeting a file-backed
namespace, nvmet_execute_identify_ns_zns() calls bdev_is_zoned() on
req->ns->bdev. A file-backed namespace has no block device, so
req->ns->bdev is NULL and bdev_is_zoned() dereferences it, oopsing.

The I/O command set is selected by the host-supplied CSI field and the
command is routed here whenever CONFIG_BLK_DEV_ZONED is enabled,
independent of the namespace backing type, so any file-backed namespace
is exposed.

Reject the command with Invalid Field when the namespace is not backed
by a block device.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A NULL pointer dereference occurs in the Linux kernel NVMe target driver when a host issues an Identify command with CNS 05h and CSI 02h to a file‑backed namespace. The function nvmet_execute_identify_ns_zns calls bdev_is_zoned() on req->ns->bdev; for a file‑backed namespace this pointer is NULL, causing a kernel crash. The crash represents a denial‑of‑service event because the kernel panics when the faulty path is exercised. This flaw is a classic Null Pointer Dereference vulnerability (CWE‑476).

Affected Systems

The flaw affects the Linux kernel in any build that enables NVMe target support and the CONFIG_BLK_DEV_ZONED option. All versions of the kernel that include a file‑backed namespace and this option are potentially vulnerable. No specific kernel release is listed in the data, so any kernel with these features prior to the applied patch is at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. The EPSS probability is less than 1 %, implying a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based through an NVMe target, as the flaw is triggered when a host sends an Identify command with specific parameters. Based on the description, it is inferred that no special authentication or privilege escalation is required beyond simply having connectivity to the NVMe service. The crash occurs in kernel code and would result in a system interruption, not remote code execution.

Generated by OpenCVE AI on September 20, 2026 at 03:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the commit that fixes the null pointer dereference; the patch is referenced in the CVE description with commit URLs.
  • If an immediate kernel upgrade is not possible, rebuild the kernel without the CONFIG_BLK_DEV_ZONED option or disable zoned block device support for NVMe targets to eliminate the code path that performs the NULL dereference.
  • Restrict or filter NVMe Identify commands that target file‑backed namespaces; if possible, configure the target host to reject CSI 02h requests for these namespaces through access control or firmware settings.

Generated by OpenCVE AI on September 20, 2026 at 03:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Sat, 19 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns() When a host issues an Identify command with CNS 05h (I/O Command Set specific Identify Namespace) and CSI 02h (ZNS) targeting a file-backed namespace, nvmet_execute_identify_ns_zns() calls bdev_is_zoned() on req->ns->bdev. A file-backed namespace has no block device, so req->ns->bdev is NULL and bdev_is_zoned() dereferences it, oopsing. The I/O command set is selected by the host-supplied CSI field and the command is routed here whenever CONFIG_BLK_DEV_ZONED is enabled, independent of the namespace backing type, so any file-backed namespace is exposed. Reject the command with Invalid Field when the namespace is not backed by a block device.
Title nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:55.044Z

Reserved: 2026-09-11T19:38:34.794Z

Link: CVE-2026-90228

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:18.517

Modified: 2026-09-18T18:17:47.650

Link: CVE-2026-90228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:45:12Z

Weaknesses

No weakness.