Description
In the Linux kernel, the following vulnerability has been resolved:

nvmet: fix return status of RMI log page on allocation failure

nvmet_execute_get_log_page_rmi() leaves 'status' holding NVME_SC_SUCCESS
(set by the successful nvmet_req_find_ns() call) when the kzalloc() for
the log buffer fails. It then jumps to the out label and completes the
request with a success status, so the host is told the command succeeded
while no data was transferred.

Initialize 'status' to NVME_SC_INTERNAL, matching the smart log handler,
so an allocation failure is reported as an internal error.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Inaccurate success status returned for NVMe log page requests
Action: Apply Patch
AI Analysis

Impact

The Linux kernel contains a bug in nvmet_execute_get_log_page_rmi where a failure to allocate the log buffer leaves the status variable set to a success code. The host is thus told the NVMe over Fabrics RMI log page read command succeeded even though no data was transferred, misleading the system operator about the state of the command.

Affected Systems

The vulnerability affects Linux kernel systems that support NVMe over Fabrics. No specific kernel version range is listed in the advisory, but the issue has been fixed in recent kernel commits referenced in the advisory links.

Risk and Exploitability

The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV, indicating a very low probability of exploitation. The flaw does not provide a direct code‑execution path or other high‑impact attack surface; it simply misreports success, which could lead to data unavailability or operational confusion.

Generated by OpenCVE AI on September 19, 2026 at 13:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes commit 581d8bb or 9e13615, which initializes the status correctly.
  • If the vendor has not backported the fix, manually apply the upstream patch to your kernel source, rebuild, and install the updated kernel.
  • Request or wait for the vendor to release a backported patch for your supported kernel version.

Generated by OpenCVE AI on September 19, 2026 at 13:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nvmet: fix return status of RMI log page on allocation failure nvmet_execute_get_log_page_rmi() leaves 'status' holding NVME_SC_SUCCESS (set by the successful nvmet_req_find_ns() call) when the kzalloc() for the log buffer fails. It then jumps to the out label and completes the request with a success status, so the host is told the command succeeded while no data was transferred. Initialize 'status' to NVME_SC_INTERNAL, matching the smart log handler, so an allocation failure is reported as an internal error.
Title nvmet: fix return status of RMI log page on allocation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:38.732Z

Reserved: 2026-09-11T19:38:34.812Z

Link: CVE-2026-90412

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:43.000

Modified: 2026-09-17T17:17:43.000

Link: CVE-2026-90412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:00:15Z

Weaknesses