Database/Kernel, userspace & hypervisor
Linux kernel - NVMe-oF target configfs, drivers/nvme/target/configfs.c: Nvmet_root_discovery_nqn_store() treated the
Impact
Nvmet_root_discovery_nqn_store() treated the subsystem NQN string as a fixed-size buffer even though it is dynamically allocated to the length of the existing string, so writing a longer discovery NQN overflows the allocation. The direct exposure is local to whoever administers the target's configfs, but in an operator context that includes storage orchestration and CSI drivers running with elevated privileges - so a compromised control-plane component turns a configuration write into kernel memory corruption on the node holding every tenant's namespaces. It also matters because NQN handling is exactly the surface an attacker probes when attempting NQN spoofing.
Who can reach it
Write an over-long NQN string to the discovery subsystem's configfs attribute on the target. Requires privileged access to the target host's configfs, which orchestration and storage-management agents routinely have. Not remotely reachable on its own, but a natural second stage after compromising a storage control-plane component.
What to do
Host reboot / kernel upgrade on nvmet target nodes; fold into the same window as the other nvmet findings rather than scheduling separately. Config-side hardening that pays off regardless: keep the target's configfs off any path an untrusted orchestration component can reach, and audit which service accounts can write nvmet configuration.
References
Related entries
- polkit: out-of-bounds write parsing deeply nested XML policy filesCVE-2025-7519 · polkit (XML policy parser, nested-element depth)Medium
- systemd-homed: local homed-managed user can gain membership in arbitrary system groupsCVE-2026-16742 · systemd-homed (homed-managed user record group membership)Medium
- systemd-machined: unvalidated RegisterMachine class lets a local user reach root command executionCVE-2026-4105 · systemd-machined (RegisterMachine D-Bus method, class parameter validation)Medium
- QEMU virtio-blk: malformed guest SCSI request causes host-heap out-of-bounds writeCVE-2026-48914 · QEMU virtio-blk device (SCSI request descriptor size validation)Medium
- Linux kernel (AF_UNIX): Use-after-free in unix_stream_sendpage - local privilege escalation, no capabilities neededCVE-2023-4622 · Linux kernel (AF_UNIX)Medium
- Linux kernel (net/sched ETS): Out-of-bounds indexing in the ETS qdisc - memory corruption from CAP_NET_ADMINCVE-2025-21692 · Linux kernel (net/sched ETS)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.