Description
In the Linux kernel, the following vulnerability has been resolved:

nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()

nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with
the host-supplied transfer length (tl) and hands it to
nvmet_auth_negotiate() without passing tl along. nvmet_auth_negotiate()
then reads the negotiate header and, for each of the halen hash
identifiers and dhlen DH group identifiers, indexes into the fixed
idlist[60] array (hashes at idlist[0..halen), groups at idlist[30..]).

Neither the transfer length nor halen/dhlen is validated. A malicious or
non-conformant host can report a tl smaller than the negotiate structure,
or a halen/dhlen larger than the array (both are u8, up to 255), making
the loops read past the end of the allocated buffer (heap out-of-bounds
read). The sibling nvmet_auth_reply() already validates tl against the
structure size; the negotiate path did not.

Pass tl into nvmet_auth_negotiate(), reject a tl that does not cover the
negotiate data plus one full protocol descriptor, and reject halen/dhlen
larger than NVME_AUTH_DHCHAP_MAX_DH_IDS.
Published: 2026-09-17
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel, the nvmet module incorrectly processes HMAC-CHAP authentication negotiation messages. The code allocates a buffer based on a host-supplied transfer length but fails to forward that length to the parsing function, and it does not validate the number of hash or DH group identifiers reported by the host. When a host supplies a transfer length smaller than the negotiation structure or values for the number of identifiers larger than the internal array limits, the code indexes past the end of the buffer, resulting in a heap out-of-bounds read. An attacker controlling the host can therefore cause the kernel to read arbitrary memory from the heap, potentially leaking sensitive kernel data. The vulnerability does not directly lead to code execution but can expose confidential information and weaken overall system security.

Affected Systems

Linux kernel implementations that expose NVMe‑over‑Fabrics target functionality, particularly versions that have not incorporated the recent patch correcting nvmet_auth_negotiate(). The affected product is the Linux operating system kernel; specific affected versions are all kernels released before the fix was merged.

Risk and Exploitability

The CVSS score of 9.1 places this issue in the High‑severity category, indicating serious potential impact. The EPSS score is less than 1 %, suggesting that at the time of this analysis the likelihood of exploitation is low, though the vulnerability remains present. It is not listed in the CISA KEV catalog, but competent adversaries could exploit it via a non‑conformant or malicious NVMe host that initiates a negotiation with oversized identifiers or a truncated transfer length. Because the flaw triggers an information‑disclosure read from the kernel heap, an attacker could gather sensitive data from memory. The attack vector is inferred to be a remote or local host communicating with an NVMe target, as the vulnerable logic resides in the NVMe target's authentication path.

Generated by OpenCVE AI on September 20, 2026 at 02:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the commit correcting nvmet_auth_negotiate()
  • Ensure the NVMe‑over‑Fabrics target is running the patched kernel and that all related drivers are updated
  • If an update cannot be applied immediately, configure the NVMe target to enforce strict host compliance by rejecting negotiate messages that specify unsupported HMAC‑CHAP parameters or malformed transfer lengths

Generated by OpenCVE AI on September 20, 2026 at 02:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Sat, 19 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with the host-supplied transfer length (tl) and hands it to nvmet_auth_negotiate() without passing tl along. nvmet_auth_negotiate() then reads the negotiate header and, for each of the halen hash identifiers and dhlen DH group identifiers, indexes into the fixed idlist[60] array (hashes at idlist[0..halen), groups at idlist[30..]). Neither the transfer length nor halen/dhlen is validated. A malicious or non-conformant host can report a tl smaller than the negotiate structure, or a halen/dhlen larger than the array (both are u8, up to 255), making the loops read past the end of the allocated buffer (heap out-of-bounds read). The sibling nvmet_auth_reply() already validates tl against the structure size; the negotiate path did not. Pass tl into nvmet_auth_negotiate(), reject a tl that does not cover the negotiate data plus one full protocol descriptor, and reject halen/dhlen larger than NVME_AUTH_DHCHAP_MAX_DH_IDS.
Title nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:57.758Z

Reserved: 2026-09-11T19:38:34.794Z

Link: CVE-2026-90230

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:18.803

Modified: 2026-09-18T18:17:47.987

Link: CVE-2026-90230

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:45:18Z

Weaknesses

No weakness.