{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89973","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.779Z","datePublished":"2026-09-16T10:32:52.409Z","dateUpdated":"2026-09-16T14:40:55.074Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:40:55.074Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-tcp: check the data direction of a C2HData PDU\n\nnvme_tcp_handle_c2h_data() finds the request by command id and checks\nthat it has a payload, but it does not check that the command asked for\ndata to be read.  A controller that answers a write command with C2HData\ntherefore reaches nvme_tcp_recv_data(), where _copy_to_iter() hits\nWARN_ON_ONCE(i->data_source) and returns 0.  The receive path turns that\ninto -EFAULT and resets the controller.\n\nNo data is copied, so this is not memory corruption.  What a controller\ngets is a kernel warning it can raise at will, which is fatal on a host\nbooted with panic_on_warn.\n\nThe send path already knows the direction - it consults rq_data_dir()\nwhen it builds a command - and nvme_tcp_handle_r2t() checks the length\nand the offset of the request it names.  The C2HData path does not check\nthe direction at all.\n\nReject a C2HData PDU whose command is not a read.  Rejecting it fails\nthe command and resets the controller, as the neighbouring check in this\nfunction does; what goes away is the warning.\n\n  [    6.885580] ------------[ cut here ]------------\n  [    6.886457] WARNING: lib/iov_iter.c:193 at _copy_to_iter+0x289/0x1330, CPU#0: kworker/0:1H/71\n  [    6.888137] CPU: 0 UID: 0 PID: 71 Comm: kworker/0:1H Not tainted 7.2.0-rc5-NVMETCP-gf5098b6bae76 #1 PREEMPT(lazy)\n  [    6.891165] Workqueue: nvme_tcp_wq nvme_tcp_io_work\n  [    6.891875] RIP: 0010:_copy_to_iter+0x289/0x1330\n  [    6.903739] Call Trace:\n  [    6.904085]  <TASK>\n  [    6.909254]  __skb_datagram_iter+0x433/0x820\n  [    6.911026]  skb_copy_datagram_iter+0x37/0x120\n  [    6.911622]  nvme_tcp_recv_skb+0xa07/0x4320\n  [    6.913378]  __tcp_read_sock+0x1ab/0x810\n  [    6.915788]  nvme_tcp_try_recv+0x152/0x1e0\n  [    6.918222]  nvme_tcp_io_work+0x1e4/0x6c0\n  [    6.926906]  </TASK>\n  [    6.927226] ---[ end trace 0000000000000000 ]---\n  [    6.927878] nvme nvme0: queue 1 failed to copy request 0x71 data\n  [    6.928709] nvme nvme0: receive failed:  -14"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":8.2,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The nvme-tcp host receive path (nvme_tcp_data_ready -> nvme_tcp_try_recv -> nvme_tcp_recv_skb -> nvme_tcp_handle_c2h_data) parses C2HData PDUs from a remote NVMe/TCP target over routable TCP (typically port 4420); a malicious or compromised target, or an on-path injector into the default-unencrypted stream, triggers the bug from the network.\nAC:L - A malicious controller that replies to any in-flight write-direction command with a well-formed C2HData PDU always hits WARN_ON_ONCE(i->data_source) in _copy_to_iter; writes occur from writeback, discards, and init-time Set Features. No race, special memory layout, or rare config beyond CONFIG_NVME_TCP is required.\nPR:N - NVMe/TCP authentication (TLS and DH-HMAC-CHAP) is optional and off by default, so the connected fabric peer needs no credentials or privileges on the victim host; it simply answers I/O the host is already sending.\nUI:N - No victim action is required at exploit time; once the host is connected (including nvmf-autoconnect at boot), ordinary writeback, journal I/O, and controller-init Set Features with a data buffer issue write-direction commands that the malicious target answers with C2HData.\nS:U - The WARN splat, NVMe controller reset, and any panic_on_warn crash remain inside the host kernel. This is not a VM escape, IOMMU bypass, or sandbox boundary crossing.\nC:L - WARN_ON_ONCE in _copy_to_iter calls __warn()/dump_stack(), disclosing kernel text addresses in dmesg. No data is copied (the write iterator is ITER_SOURCE and copy_to_iter returns 0), so there is no use-after-free or arbitrary kernel read.\nI:N - The receive path turns the failed copy into -EFAULT and resets the controller; _copy_to_iter returns 0 without writing, so there is no memory corruption, write primitive, or control-flow hijack.\nA:H - The reporter reproduced WARNING in _copy_to_iter from nvme_tcp_io_work, which panics hosts with panic_on_warn or warn_limit. Independently, every C2HData-for-write returns -EFAULT and runs nvme_tcp_error_recovery(), so a malicious target can repeatedly take down NVMe-oF storage."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/nvme/host/tcp.c"],"versions":[{"version":"3f2304f8c6d6ed97849057bd16fee99e434ca796","lessThan":"df74950ba6008655d4a977d17df7faf4b6e52b74","status":"affected","versionType":"git"},{"version":"3f2304f8c6d6ed97849057bd16fee99e434ca796","lessThan":"980d990f3c0560d7dfbfbf14699651fdf02f26ee","status":"affected","versionType":"git"},{"version":"3f2304f8c6d6ed97849057bd16fee99e434ca796","lessThan":"5b115d932f6e769ac80783fb18edd21b0aed256e","status":"affected","versionType":"git"},{"version":"3f2304f8c6d6ed97849057bd16fee99e434ca796","lessThan":"0673a2affe45ca76b60de31a83c67b1e60f81bde","status":"affected","versionType":"git"},{"version":"3f2304f8c6d6ed97849057bd16fee99e434ca796","lessThan":"80d56202fbdff8906be6954b2776e5c14a4026f2","status":"affected","versionType":"git"},{"version":"3f2304f8c6d6ed97849057bd16fee99e434ca796","lessThan":"b4af7999a998787d5eb6facb5a333e04a4f1d2d9","status":"affected","versionType":"git"},{"version":"3f2304f8c6d6ed97849057bd16fee99e434ca796","lessThan":"a0c389b8a495bda1eb719d2503853c924b7a8355","status":"affected","versionType":"git"},{"version":"3f2304f8c6d6ed97849057bd16fee99e434ca796","lessThan":"f83af377c148f6ad94b41c0e8313f12adf45e1c1","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/nvme/host/tcp.c"],"versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"7.3-rc2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/df74950ba6008655d4a977d17df7faf4b6e52b74"},{"url":"https://git.kernel.org/stable/c/980d990f3c0560d7dfbfbf14699651fdf02f26ee"},{"url":"https://git.kernel.org/stable/c/5b115d932f6e769ac80783fb18edd21b0aed256e"},{"url":"https://git.kernel.org/stable/c/0673a2affe45ca76b60de31a83c67b1e60f81bde"},{"url":"https://git.kernel.org/stable/c/80d56202fbdff8906be6954b2776e5c14a4026f2"},{"url":"https://git.kernel.org/stable/c/b4af7999a998787d5eb6facb5a333e04a4f1d2d9"},{"url":"https://git.kernel.org/stable/c/a0c389b8a495bda1eb719d2503853c924b7a8355"},{"url":"https://git.kernel.org/stable/c/f83af377c148f6ad94b41c0e8313f12adf45e1c1"}],"title":"nvme-tcp: check the data direction of a C2HData PDU","x_generator":{"engine":"bippy-1.2.0"}}}}