{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89481","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.711Z","datePublished":"2026-09-11T19:43:36.589Z","dateUpdated":"2026-09-14T12:00:18.149Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:18.149Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-tcp: fix host memory disclosure on R2T for a read command\n\nnvme_tcp_handle_r2t() does not check the direction of the request the\nR2T refers to. A malicious controller can send an R2T for a READ and\nthe host will answer it: nvme_tcp_setup_h2c_data_pdu() builds the\nH2CData header and nvme_tcp_try_send_data() sends the request's data\nbuffer. That buffer is the READ destination, so its contents go to the\ncontroller.\n\nThe command then completes normally and nothing is logged.\n\nAgainst a test controller that answers every READ with an R2T, a 4096\nbyte buffered read returned all 4096 bytes, split over two R2Ts. The\npages contained stale kernel data, including an array of struct page\npointers.\n\nReject an R2T for a request that is not a write."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The bug is in the NVMe-over-TCP host PDU receive path (nvme_tcp_recv_skb → nvme_tcp_handle_r2t). A remote NVMe-oF target or on-path attacker sends an R2T PDU over TCP (port 4420) and the host splices the READ destination buffer back over that socket.\nAC:L - A malicious controller that replies to an in-flight READ with a well-formed R2T always triggers the leak; the reporter reproduced a full 4096-byte disclosure with a test target. No race, special memory layout, or rare config beyond CONFIG_NVME_TCP is required.\nPR:N - NVMe/TCP requires no authentication by default (TLS and DH-HMAC-CHAP are optional and off in stock configs), so the remote peer needs no privileges or credentials on the victim host; it simply answers I/O the host is already sending.\nUI:N - No victim action is required at exploit time; once the host is connected (including via nvmf-autoconnect at boot), ordinary filesystem or block I/O issues READ commands and the malicious target triggers the leak by replying with R2T PDUs.\nS:U - The disclosure is of the host kernel's own I/O buffers and page-cache pages to the connected target. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - nvme_tcp_try_send_data() splices the READ destination pages to the attacker. Those pages hold stale kernel memory (reproduced: 4096 bytes including struct page pointers). Every subsequent READ can leak another MDTS-sized buffer of recycled kernel pages.\nI:N - The host only transmits existing buffer contents; the bug does not write attacker-controlled data into kernel memory, corrupt kernel structures, or provide a write or control-flow hijack primitive.\nA:N - The malformed R2T path completes the command successfully with nothing logged; the reporter observed a silent disclosure with no oops, panic, hang, or other availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/nvme/host/tcp.c"],"versions":[{"version":"3f2304f8c6d6ed97849057bd16fee99e434ca796","lessThan":"49a4dcf57608ebf6432dbcb203ed25e7ed581445","status":"affected","versionType":"git"},{"version":"3f2304f8c6d6ed97849057bd16fee99e434ca796","lessThan":"bc4013c7cce58d46f792c8c87bc8c8318a70190e","status":"affected","versionType":"git"},{"version":"3f2304f8c6d6ed97849057bd16fee99e434ca796","lessThan":"a4c3c7310156493797c920b10d8648c07aa05403","status":"affected","versionType":"git"},{"version":"3f2304f8c6d6ed97849057bd16fee99e434ca796","lessThan":"3b3d27670c0c890ba7cf1bc3614cab61bde6d25c","status":"affected","versionType":"git"},{"version":"3f2304f8c6d6ed97849057bd16fee99e434ca796","lessThan":"3a0b05145053a5fad1a2ddb4e4d87b07385e63e5","status":"affected","versionType":"git"},{"version":"3f2304f8c6d6ed97849057bd16fee99e434ca796","lessThan":"6efbc52237facda35d2d874fe1765bb4839275d8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/nvme/host/tcp.c"],"versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/49a4dcf57608ebf6432dbcb203ed25e7ed581445"},{"url":"https://git.kernel.org/stable/c/bc4013c7cce58d46f792c8c87bc8c8318a70190e"},{"url":"https://git.kernel.org/stable/c/a4c3c7310156493797c920b10d8648c07aa05403"},{"url":"https://git.kernel.org/stable/c/3b3d27670c0c890ba7cf1bc3614cab61bde6d25c"},{"url":"https://git.kernel.org/stable/c/3a0b05145053a5fad1a2ddb4e4d87b07385e63e5"},{"url":"https://git.kernel.org/stable/c/6efbc52237facda35d2d874fe1765bb4839275d8"}],"title":"nvme-tcp: fix host memory disclosure on R2T for a read command","x_generator":{"engine":"bippy-1.2.0"}}}}