Impact
The Linux kernel contains a bug in nvmet_execute_get_log_page_rmi where a failure to allocate the log buffer leaves the status variable set to a success code. The host is thus told the NVMe over Fabrics RMI log page read command succeeded even though no data was transferred, misleading the system operator about the state of the command.
Affected Systems
The vulnerability affects Linux kernel systems that support NVMe over Fabrics. No specific kernel version range is listed in the advisory, but the issue has been fixed in recent kernel commits referenced in the advisory links.
Risk and Exploitability
The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV, indicating a very low probability of exploitation. The flaw does not provide a direct code‑execution path or other high‑impact attack surface; it simply misreports success, which could lead to data unavailability or operational confusion.
OpenCVE Enrichment