{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64320","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T15:36:31.780Z","datePublished":"2026-07-25T08:49:48.908Z","dateUpdated":"2026-08-17T04:53:20.999Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T04:53:20.999Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page\n\nnvmet_execute_disc_get_log_page() validates only the dword alignment\nof the host-supplied Log Page Offset (lpo).  The 64-bit offset is then\nadded to a small kzalloc'd buffer that holds the discovery log page\nand the result is passed straight to nvmet_copy_to_sgl(), which\nmemcpy()s data_len bytes out to the host with no source-side bound\ncheck:\n\n    u64 offset      = nvmet_get_log_page_offset(req->cmd);  /* 64-bit host */\n    size_t data_len = nvmet_get_log_page_len(req->cmd);     /* 32-bit host */\n    ...\n    if (offset & 0x3) { ... }                               /* only check */\n    ...\n    alloc_len = sizeof(*hdr) + entry_size * discovery_log_entries(req);\n    buffer = kzalloc(alloc_len, GFP_KERNEL);\n    ...\n    status = nvmet_copy_to_sgl(req, 0, buffer + offset, data_len);\n\nThe Discovery controller is unauthenticated -- nvmet_host_allowed()\nreturns true unconditionally for the discovery subsystem -- so the call\nis reachable pre-authentication by any TCP/RDMA/FC peer that can reach\nthe nvmet target.  With a discovery log page of ~1 KiB, an attacker\nrequesting up to 4 KiB starting at offset == alloc_len reads the next\nslab page out and gets its content returned over the fabric (an\nempirical run on a default nvmet-tcp loopback target leaked 81\ncanonical kernel pointers in one Get Log Page response).  Pointing the\noffset at unmapped kernel memory faults the in-kernel memcpy and\ncrashes (or panics, on panic_on_oops=1) the target host instead.\n\nThe attacker-controlled source-side offset pattern\n\"nvmet_copy_to_sgl(req, 0, buffer + ATTACKER_OFFSET, ...)\" is unique\nto nvmet_execute_disc_get_log_page in the entire nvmet codebase: every\nother Get Log Page handler in admin-cmd.c either ignores lpo (and\nsilently starts every response at offset 0) or tracks a local\ndestination offset with a fixed source pointer.\n\nValidate the host-supplied offset against the log page size, cap the\ncopy length to what is actually available, and zero-fill any remainder\nof the host transfer buffer.  The zero-fill matches the existing\nshort-response pattern in nvmet_execute_get_log_changed_ns()\n(admin-cmd.c) and prevents leaking transport SGL contents when the\nhost asks for more bytes than the log page contains."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":9.1,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The vulnerable discovery command is remotely reachable through routable NVMe/TCP, as well as NVMe/RDMA and FC transports.\nAC:L - The attacker controls the protocol sequence, transfer length, and aligned 64-bit offset, with no race or condition outside their control.\nPR:N - The discovery subsystem accepts every Host NQN and explicitly skips DH-HMAC-CHAP authentication, making the command reachable pre-authentication.\nUI:N - No victim action is required after the NVMe-oF target port is available.\nS:U - The disclosure and crash affect the vulnerable target kernel within the same security authority.\nC:H - The unbounded offset permits repeated multi-kilobyte kernel heap disclosures; testing cited by the fix exposed 81 canonical kernel pointers in one response.\nI:N - The primitive reads target memory into transport response pages but provides no attacker-selected write to target memory.\nA:H - An offset resolving to unmapped or noncanonical memory faults the in-kernel memcpy, causing an oops or target-host panic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/nvme/target/discovery.c"],"versions":[{"version":"a07b4970f464f13640e28e16dad6cfa33647cc99","lessThan":"33b974eb626154ae9348f2bac7de84cb2a3d9dd4","status":"affected","versionType":"git"},{"version":"a07b4970f464f13640e28e16dad6cfa33647cc99","lessThan":"56c021a0869260d04c4b65d1471936aaf9177114","status":"affected","versionType":"git"},{"version":"a07b4970f464f13640e28e16dad6cfa33647cc99","lessThan":"a29b316b9bbfd269f323ab4ba9906a894025680f","status":"affected","versionType":"git"},{"version":"a07b4970f464f13640e28e16dad6cfa33647cc99","lessThan":"53cd102a7a56079b11b897835bd9b94c14e6322c","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/nvme/target/discovery.c"],"versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","status":"unaffected","versionType":"semver"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.12.96"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.18.39"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.1.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/33b974eb626154ae9348f2bac7de84cb2a3d9dd4"},{"url":"https://git.kernel.org/stable/c/56c021a0869260d04c4b65d1471936aaf9177114"},{"url":"https://git.kernel.org/stable/c/a29b316b9bbfd269f323ab4ba9906a894025680f"},{"url":"https://git.kernel.org/stable/c/53cd102a7a56079b11b897835bd9b94c14e6322c"}],"title":"nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page","x_generator":{"engine":"bippy-1.2.0"}}}}