{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90230","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.794Z","datePublished":"2026-09-17T16:07:37.940Z","dateUpdated":"2026-09-18T17:53:57.758Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:53:57.758Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()\n\nnvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with\nthe host-supplied transfer length (tl) and hands it to\nnvmet_auth_negotiate() without passing tl along. nvmet_auth_negotiate()\nthen reads the negotiate header and, for each of the halen hash\nidentifiers and dhlen DH group identifiers, indexes into the fixed\nidlist[60] array (hashes at idlist[0..halen), groups at idlist[30..]).\n\nNeither the transfer length nor halen/dhlen is validated. A malicious or\nnon-conformant host can report a tl smaller than the negotiate structure,\nor a halen/dhlen larger than the array (both are u8, up to 255), making\nthe loops read past the end of the allocated buffer (heap out-of-bounds\nread). The sibling nvmet_auth_reply() already validates tl against the\nstructure size; the negotiate path did not.\n\nPass tl into nvmet_auth_negotiate(), reject a tl that does not cover the\nnegotiate data plus one full protocol descriptor, and reject halen/dhlen\nlarger than NVME_AUTH_DHCHAP_MAX_DH_IDS."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":9.1,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The malformed bytes are the DH-HMAC-CHAP Negotiate payload of an NVMe-oF Authentication Send capsule (cmd->auth_send.tl). nvmet-tcp receives that capsule in nvmet_tcp_try_recv_pdu/nvmet_tcp_try_recv_data, nvmet_copy_from_sgl copies it, and nvmet_auth_negotiate() parses it; NVMe/TCP is IP-routable.\nAC:L - Unpatched nvmet_auth_negotiate() never checks tl, halen, or dhlen. A host that sets auth_send.tl below 72 bytes (negotiate header plus nvmf_auth_dhchap_protocol_descriptor) and/or sets the u8 halen/dhlen fields to 255 makes the idlist[i] and idlist[i+30] loops deterministically over-read kmalloc(tl) with no race.\nPR:N - nvmet_parse_admin_cmd routes fabrics opcodes to nvmet_parse_fabrics_admin_cmd before nvmet_check_ctrl_status(), so AUTH_SEND runs without nvmet_check_auth_status(). sq->dhchap_step starts at NEGOTIATE, and nvmet_host_allowed() always permits nqn.2014-08.org.nvmexpress.discovery, so no DH-HMAC-CHAP secret is required.\nUI:N - The attacker opens a TCP connection to an already-listening nvmet-tcp port, sends Connect, then Authentication Send carrying the short or over-long DH-HMAC-CHAP Negotiate buffer; no victim mount, file open, or prompt is required.\nS:U - The over-read is of the kmalloc(tl) DH-HMAC-CHAP buffer and adjacent slab on the NVMe target host; it does not cross a VM, hypervisor, or IOMMU boundary.\nC:H - With tl shorter than the 72-byte negotiate-plus-descriptor layout, or with u8 halen/dhlen up to 255 against idlist[60], nvmet_auth_negotiate() heap-over-reads hundreds of bytes of adjacent slab via idlist[i] and idlist[i+30], which is not a few-byte leak.\nI:N - nvmet_auth_negotiate() only loads header fields and idlist[] entries and does not write past the allocation. Assigning ctrl->shash_id or ctrl->dh_gid from a parsed identifier is an in-bounds field update, not an OOB write or hijack primitive.\nA:H - Walking idlist[] hundreds of bytes past a small kmalloc(tl) AUTH_SEND object can oops if the read hits an unmapped page or a KASAN/KFENCE redzone, and the initiator can repeat Authentication Send on new connections to the same target."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/nvme/target/fabrics-cmd-auth.c"],"versions":[{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"89ff11b72f38976f3b5aea23a5228ee05e277209","status":"affected","versionType":"git"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"aaac783950b17c57df9b6f7344747cacb1a407ed","status":"affected","versionType":"git"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"c38a8186326799957d293d370136c128cd113916","status":"affected","versionType":"git"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"7b81e4d2230e3d2d372c826180c4ef0efc244f31","status":"affected","versionType":"git"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"5bb96cc218835769ab74ec7f3ea2bf81fbffe955","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/nvme/target/fabrics-cmd-auth.c"],"versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/89ff11b72f38976f3b5aea23a5228ee05e277209"},{"url":"https://git.kernel.org/stable/c/aaac783950b17c57df9b6f7344747cacb1a407ed"},{"url":"https://git.kernel.org/stable/c/c38a8186326799957d293d370136c128cd113916"},{"url":"https://git.kernel.org/stable/c/7b81e4d2230e3d2d372c826180c4ef0efc244f31"},{"url":"https://git.kernel.org/stable/c/5bb96cc218835769ab74ec7f3ea2bf81fbffe955"}],"title":"nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()","x_generator":{"engine":"bippy-1.2.0"}}}}