Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-64535

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 6.5

Описание

A use-after-free flaw was found in the Linux kernel's NVMe-over-Fabrics TCP target (nvmet-tcp) driver. When NVMe/TCP data digest is enabled and a digest mismatch occurs on a non-final H2C_DATA PDU during an R2T-based write transfer, the digest error handler in nvmet_tcp_try_recv_ddgst() calls nvmet_req_uninit(), which drops a percpu_ref reference on the submission queue without marking the command as completed. During the subsequent queue teardown, the same command is treated as still needing data and nvmet_req_uninit() is called a second time, resulting in a double percpu_ref_put against a single percpu_ref_get. This use-after-free and reference-count underflow can crash the kernel (denial of service) when a remote NVMe/TCP initiator triggers a digest mismatch against a host configured as an NVMe/TCP target.

Отчет

This flaw is a use-after-free and reference-count underflow in the Linux kernel's NVMe-over-Fabrics TCP target driver (nvmet-tcp). When NVMe/TCP data digest is enabled and a digest mismatch occurs on a non-final H2C_DATA PDU during an R2T-based write transfer, the digest error handler in nvmet_tcp_try_recv_ddgst() calls nvmet_req_uninit(), which drops a percpu_ref reference on the submission queue without marking the command as completed. During the subsequent queue teardown, the same command is still treated as needing data and nvmet_req_uninit() is called a second time, causing a double percpu_ref_put against a single percpu_ref_get. This can lead to a use-after-free and crash the kernel (denial of service). This flaw is only reachable on systems that have been explicitly and manually configured to act as an NVMe-over-Fabrics TCP target (nvmet-tcp), for example by using the nvmetcli tool to export local block devices as an NVMe subsystem over a TCP network. Red Hat does not support the NVMe Target (nvmet) functionality in Red Hat Enterprise Linux; nvmet-tcp shipped as Technology Preview starting in RHEL 7.6 and continues to ship as Unmaintained in RHEL 8 and RHEL 9 and later. The NVMe/TCP host/initiator driver (nvme_tcp), which is fully supported for connecting to external NVMe/TCP storage, does not contain the affected code path and is not impacted by this issue. Systems that have not explicitly configured themselves as an NVMe/TCP target are not exposed to this vulnerability. Red Hat Enterprise Linux 6 does not ship any NVMe-over-Fabrics support (host or target) and is not affected. Red Hat Enterprise Linux 7's Technology Preview nvmet-tcp module is frozen at an older upstream baseline that predates the vulnerable code path introduced by this flaw, so RHEL 7 is also not affected, consistent with Red Hat's disposition on two prior nvmet-tcp vulnerabilities (CVE-2026-22998, CVE-2026-46135). Exploitation requires the attacking NVMe/TCP initiator to already have network access to a deliberately configured, unsupported NVMe/TCP target, which is typically reachable only from the same storage or data-center network segment rather than from the public Internet. Accordingly, the attack vector has been scored as Adjacent (AV:A) rather than Network (AV:N), consistent with Red Hat's CVSS treatment of the two prior nvmet-tcp CVEs referenced above.

Меры по смягчению последствий

There is no mitigation for this issue other than applying the kernel update once available. Because Red Hat does not support and does not enable the nvmet-tcp target functionality by default, systems that have not been explicitly configured with nvmetcli to act as an NVMe-over-Fabrics TCP target are not exposed and require no immediate action. Administrators who have deliberately configured an NVMe/TCP target using this unsupported functionality should restrict network access to the target port to trusted initiators on the same storage network only, and should consider disabling NVMe/TCP data digest or migrating off nvmet-tcp given its unmaintained status, until the fix is applied.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelFix deferred
Red Hat Enterprise Linux 10libkrunNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelFix deferred
Red Hat Enterprise Linux 8kernel-rtFix deferred
Red Hat Enterprise Linux 9kernelFix deferred
Red Hat Enterprise Linux 9kernel-rtFix deferred
Red Hat Enterprise Linux for NVIDIA 26kernelFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1341
https://bugzilla.redhat.com/show_bug.cgi?id=2507404kernel: nvmet-tcp: Fix potential UAF when ddgst mismatch

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
5 дней назад

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch occurs on a non-final H2C_DATA PDU during an R2T-based data transfer, the digest error handler in nvmet_tcp_try_recv_ddgst() calls nvmet_req_uninit() — which performs percpu_ref_put() on the submission queue — but does NOT mark the command as completed. It does not set cqe->status, does not modify rbytes_done, and does not clear any flag. When the subsequent fatal error triggers queue teardown, nvmet_tcp_uninit_data_in_cmds() iterates all commands, checks nvmet_tcp_need_data_in() for each one, and finds that the already-uninited command still appears to need data (because rbytes_done < transfer_len and cqe->status == 0). It therefore calls nvmet_req_uninit() a second time on the same command — a double percpu_ref_put against a single percpu_r...

CVSS3: 9.8
nvd
5 дней назад

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch occurs on a non-final H2C_DATA PDU during an R2T-based data transfer, the digest error handler in nvmet_tcp_try_recv_ddgst() calls nvmet_req_uninit() — which performs percpu_ref_put() on the submission queue — but does NOT mark the command as completed. It does not set cqe->status, does not modify rbytes_done, and does not clear any flag. When the subsequent fatal error triggers queue teardown, nvmet_tcp_uninit_data_in_cmds() iterates all commands, checks nvmet_tcp_need_data_in() for each one, and finds that the already-uninited command still appears to need data (because rbytes_done < transfer_len and cqe->status == 0). It therefore calls nvmet_req_uninit() a second time on the same command — a double percpu_ref_put against a single percpu_re

CVSS3: 9.8
debian
5 дней назад

In the Linux kernel, the following vulnerability has been resolved: n ...

CVSS3: 9.8
github
5 дней назад

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch occurs on a non-final H2C_DATA PDU during an R2T-based data transfer, the digest error handler in nvmet_tcp_try_recv_ddgst() calls nvmet_req_uninit() — which performs percpu_ref_put() on the submission queue — but does NOT mark the command as completed. It does not set cqe->status, does not modify rbytes_done, and does not clear any flag. When the subsequent fatal error triggers queue teardown, nvmet_tcp_uninit_data_in_cmds() iterates all commands, checks nvmet_tcp_need_data_in() for each one, and finds that the already-uninited command still appears to need data (because rbytes_done < transfer_len and cqe->status == 0). It therefore calls nvmet_req_uninit() a second time on the same command — a double percpu_ref_put against a single percpu...

6.5 Medium

CVSS3