Database/Kernel, userspace & hypervisor
Linux kernel (drivers/nvme/host): The PRP list mempool is sized in the wrong units, so a large I/O that needs two PRP
Impact
The PRP list mempool is sized in the wrong units, so a large I/O that needs two PRP lists writes past the end of the pool allocation. This is a genuine heap overflow on the local NVMe data path - kfence caught it in practice - so one tenant's I/O can corrupt kernel memory belonging to the rest of the node.
Who can reach it
Reachable by any unprivileged process on the node that can issue I/O to a local PCIe NVMe device (a container with a scratch volume is enough) - no /dev/nvme passthrough required. The window is narrow: it needs roughly a 4MB transfer split into 127 physical segments on a submission queue whose controller does not support SGLs. Most enterprise NVMe negotiates SGLs and is therefore not on this path, so check controller capability before rating this urgent on a given SKU.
What to do
No fixed version is listed on this record - boot a kernel carrying the linked stable commits. Interim: confirm whether the node's NVMe controllers advertise SGL support (SGL-capable queues do not take this path), and cap the maximum I/O size handed to tenants on any controller that does not.
References
Related entries
- Linux kernel (drivers/nvme/host): The NVMe/RDMA initiator destroys the queue pair before the connection manager ID, soCVE-2021-47378 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): On the NVMe/RDMA initiator, an async-event command can be submitted against an adminCVE-2022-48788 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): Same race as the RDMA variant but on NVMe/TCP, which is the far more common fabric inCVE-2022-48789 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): The multipath sibling list is walked without SRCU protection during path revalidationCVE-2022-49003 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): A discard (TRIM) request that is retried and fails again before a fresh payload isCVE-2024-41073 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): An off-by-one in the Flexible Data Placement index check accepts a placement indexCVE-2026-74361 · Linux kernel (drivers/nvme/host)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.