Database/Kernel, userspace & hypervisor
Linux kernel - NVMe-oF TCP target, drivers/nvme/target/tcp.c: The NVMe/TCP target used the host-supplied Transfer Tag
Impact
The NVMe/TCP target used the host-supplied Transfer Tag directly as an array index to look up the command structure, with no bounds check. A connected initiator sets an arbitrary ttag in an H2C Data PDU and the target reads and operates on memory outside the command array - remote out-of-bounds access on the storage node with full confidentiality, integrity and availability impact. Because NVMe/TCP requires no authentication by default, the 'connected initiator' bar is effectively 'anyone who can reach port 4420'. This one has been in shipping kernels since NVMe/TCP target support landed and was only assigned a CVE retroactively, so long-lived storage nodes are the ones to check.
Who can reach it
Open an NVMe/TCP connection to the target and send an H2CData PDU with an out-of-range Transfer Tag. No authentication needed unless DH-HMAC-CHAP has been explicitly configured. Reachable across any routed path to the target port.
What to do
Host reboot / kernel upgrade - and specifically check long-lived storage nodes, since the fix was backported late and a node that has not been rebooted in a year may still be exposed. Interim: firewall NVMe/TCP 4420 to known initiators and enable in-band DH-HMAC-CHAP on a patched kernel so the connection itself requires credentials. Roll targets in waves behind multipath so tenants see no outage.
References
Related entries
- Linux kernel - NVMe-oF TCP target, drivers/nvme/target/tcp.c: A host sending an H2CData command with a DATALCVE-2023-52454 · Linux kernel - NVMe-oF TCP target, drivers/nvme/target/tcp.cHigh
- VMware vCenter: Out-of-bounds write in the DCERPC implementation - unauthenticated remote code executionCVE-2023-34048 · VMware vCenterCritical
- OpenSSH (ssh-agent): Remote code execution in ssh-agent PKCS#11 support when agent forwarding reaches a hostile hostCVE-2023-38408 · OpenSSH (ssh-agent)Critical
- Linux kernel NVMe target core (nvmet_req_complete submission-queue dereference): Nvmet_req_complete() dereferenced reqCVE-2023-53116 · Linux kernel NVMe target core (nvmet_req_complete submission-queue dereference)Critical
- Linux kernel (net/smc): When an incoming connection tries SMC-Rv2 and device setup fails, the listener does not resetCVE-2023-53382 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): On the server side of the SMC-R LLC handshake, adding a second link to a link group runsCVE-2023-54237 · Linux kernel (net/smc)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.