๐Ÿ” CVE Alert

CVE-2026-90230

UNKNOWN 0.0

nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with the host-supplied transfer length (tl) and hands it to nvmet_auth_negotiate() without passing tl along. nvmet_auth_negotiate() then reads the negotiate header and, for each of the halen hash identifiers and dhlen DH group identifiers, indexes into the fixed idlist[60] array (hashes at idlist[0..halen), groups at idlist[30..]). Neither the transfer length nor halen/dhlen is validated. A malicious or non-conformant host can report a tl smaller than the negotiate structure, or a halen/dhlen larger than the array (both are u8, up to 255), making the loops read past the end of the allocated buffer (heap out-of-bounds read). The sibling nvmet_auth_reply() already validates tl against the structure size; the negotiate path did not. Pass tl into nvmet_auth_negotiate(), reject a tl that does not cover the negotiate data plus one full protocol descriptor, and reject halen/dhlen larger than NVME_AUTH_DHCHAP_MAX_DH_IDS.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
db1312dd95488b5e6ff362ff66fcf953a46b1821 < 89ff11b72f38976f3b5aea23a5228ee05e277209 db1312dd95488b5e6ff362ff66fcf953a46b1821 < aaac783950b17c57df9b6f7344747cacb1a407ed db1312dd95488b5e6ff362ff66fcf953a46b1821 < c38a8186326799957d293d370136c128cd113916 db1312dd95488b5e6ff362ff66fcf953a46b1821 < 7b81e4d2230e3d2d372c826180c4ef0efc244f31 db1312dd95488b5e6ff362ff66fcf953a46b1821 < 5bb96cc218835769ab74ec7f3ea2bf81fbffe955
Linux / Linux
6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/89ff11b72f38976f3b5aea23a5228ee05e277209 git.kernel.org: https://git.kernel.org/stable/c/aaac783950b17c57df9b6f7344747cacb1a407ed git.kernel.org: https://git.kernel.org/stable/c/c38a8186326799957d293d370136c128cd113916 git.kernel.org: https://git.kernel.org/stable/c/7b81e4d2230e3d2d372c826180c4ef0efc244f31 git.kernel.org: https://git.kernel.org/stable/c/5bb96cc218835769ab74ec7f3ea2bf81fbffe955