Database/Kernel, userspace & hypervisor
Linux kernel NVMe target authentication (nvmet-auth DH group setup): Ctrl
Impact
Ctrl->dh_key is freed on the error path of nvmet_setup_dhgroup() but not nulled, and it survives across repeated calls for the same controller, so nvmet_destroy_auth() frees it a second time. The bug lives in the DH-HMAC-CHAP negotiation - the code that decides whether a connecting initiator is who it claims to be - and a remote initiator drives it by repeating a failing DH group negotiation. Corrupting the heap from inside the authentication handshake is the worst possible place for it, because it is reachable before the handshake grants anything.
Who can reach it
Remote, pre-authentication. An initiator repeatedly negotiates an invalid DH group against the target.
What to do
Kernel update nulling dh_key after kfree_sensitive(). If in-band authentication is not required on a given subsystem, disabling DH-HMAC-CHAP removes the path; if it is required, patch the target nodes before widening initiator reachability.
References
Related entries
- OpenSSH (sshd): regreSSHion: signal-handler race in sshd giving unauthenticated remote root on glibc LinuxCVE-2024-6387 · OpenSSH (sshd)High
- Linux kernel (net/smc): The CLC prefix-match check on the listen path dereferences the destination cache entry'sCVE-2025-40168 · Linux kernel (net/smc)High
- libssh: unchecked OpenSSL error can leave a partially initialized ChaCha20 context in useCVE-2025-5987 · libssh (ChaCha20 cipher context initialization via OpenSSL)High
- OpenSSH scp: file fetched as root with -O and without -p can land setuid or setgidCVE-2026-35385 · OpenSSH scp (legacy SCP protocol mode, -O without -p)High
- Linux SLUB: krealloc __GFP_ZERO guarantee broken when red zoning is enabled without user trackingCVE-2026-64368 · Linux kernel SLUB allocator (init-on-alloc zeroing under SLAB_RED_ZONE)High
- Linux SUNRPC: unchecked percpu_counter_init leaves nfsd running on NULL per-cpu statsCVE-2026-89547 · Linux kernel SUNRPC (__svc_create per-pool percpu_counter init)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.