Database/Kernel, userspace & hypervisor
Linux kernel - NVMe/TCP host (initiator), drivers/nvme/host/tcp.c: Nvme_tcp_recv_pdu() did not validate the PDU header
Impact
Nvme_tcp_recv_pdu() did not validate the PDU header length, so with header digests enabled a target can send a packet declaring an invalid header length (for example 255) and make nvme_tcp_verify_hdgst() access memory outside the allocation and overwrite it with the calculated digest. The attack direction is target-to-initiator: a compromised or rogue storage target corrupts kernel memory on every GPU compute node that mounts from it. One storage compromise becomes fleet-wide kernel compromise, and header digests - a data-integrity feature operators turn on deliberately - are the precondition.
Who can reach it
The attacker controls an NVMe/TCP target the victim connects to, or can spoof/inject into that TCP connection, and returns a PDU with an out-of-range header length. Because NVMe/TCP has no transport authentication by default, an on-path attacker or anyone who can win a race to the discovery address can pose as the target.
What to do
Host reboot / kernel upgrade on all NVMe/TCP initiator nodes - that is the GPU compute fleet, not just storage, so plan a full rolling drain. Immediate mitigations: disable header digests on affected initiators (nvme connect option, applied on reconnect, no reboot) to remove the precondition, and enable TLS for NVMe/TCP where supported so the target's identity is proven. Also verify that discovery addresses cannot be hijacked on the storage network.
References
Related entries
- Linux kernel (net/tls): The strparser kept a stale reference to an skb that TCP had already coalesced away, and theCVE-2025-38471 · Linux kernel (net/tls)Critical
- Linux kernel (net/smc): The SMC listen worker keeps touching the SMC socket after smc_listen_out() has handed it offCVE-2025-38734 · Linux kernel (net/smc)Critical
- Linux kernel (net/tls): A zero-length record already sitting on the rx_list breaks the invariant that zero-copy decryptCVE-2025-39682 · Linux kernel (net/tls)Critical
- Linux kernel SoftiWARP transmit path (siw_qp_tx, siw_tcp_sendpages byte accounting): After do_tcp_sendpages() wasCVE-2025-39758 · Linux kernel SoftiWARP transmit path (siw_qp_tx, siw_tcp_sendpages byte accounting)Critical
- Linux kernel (net/tls): When the socket buffer is too small to hold a whole record, kTLS parses early and re-parses asCVE-2025-39946 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): If the skb clone that pins the input buffer for an async decrypt cannot be allocated, kTLSCVE-2025-40176 · Linux kernel (net/tls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.