Database/Kernel, userspace & hypervisor
Linux kernel NVMe-oF TCP target (nvmet-tcp queue command allocation failure): When command allocation for a new queue
Impact
When command allocation for a new queue fails, nr_cmds is left non-zero and the release path walks a NULL array, oopsing the target. A remote initiator induces the allocation failure by opening queues faster than the target can back them - an unauthenticated remote party choosing when the storage target for the whole cluster goes down.
Who can reach it
Remote, unauthenticated, by driving queue creation until allocation fails.
What to do
Kernel update zeroing nr_cmds on the allocation failure path. Rate-limit and allow-list initiator connections at the network layer in the meantime.
References
Related entries
- Linux kernel SMC (CLC message drain loop, unchecked sock_recvmsg return): The length field in the CLC header isCVE-2024-57791 · Linux kernel SMC (CLC message drain loop, unchecked sock_recvmsg return)High
- QEMU (NBD server): Improper synchronisation during socket closure - DoS of the QEMU NBD serverCVE-2024-7409 · QEMU (NBD server)High
- QEMU: use-after-free in the VNC WebSocket handshake crashes the VM process before client authenticationCVE-2025-11234 · QEMU QIOChannelWebsock (VNC WebSocket handshake)High
- Linux kernel (net/tls): If a page allocation fails while the TLS strparser is copying a partial record, the receiveCVE-2025-38018 · Linux kernel (net/tls)High
- Linux kernel (drivers/nvme/target): A connecting client that abandons the TCP connection at the right moment duringCVE-2025-38035 · Linux kernel (drivers/nvme/target)High
- Linux kernel (net/xfrm): Several error paths in the ESP-in-TCP receive code return without freeing the skb, soCVE-2025-38057 · Linux kernel (net/xfrm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.