Database/Firmware, BMC & network fabric
Linux kernel NVMe-oF TCP host (nvme-tcp R2T PDU request-list handling): Nvme_tcp_handle_r2t() did not check that the
Impact
Nvme_tcp_handle_r2t() did not check that the request identified by an inbound Ready-to-Transfer PDU was not already on a list, so a malicious target sends a crafted R2T and injects a loop into the initiator's request list. The commit message says it plainly - a malicious R2T PDU. Every GPU node connected to that target is affected, and the corruption is in the block-layer request path, so it sits directly under the filesystem holding checkpoints and datasets.
Who can reach it
Remote, from the target side. A hostile or compromised NVMe/TCP target, or an attacker who can inject into an unencrypted NVMe/TCP session on the storage network.
What to do
Kernel update on compute nodes validating the request state in nvme_tcp_handle_r2t(). Consider NVMe/TCP over TLS on the storage path so R2T PDUs cannot be injected by an on-path attacker, and treat the storage network as a trust boundary rather than as infrastructure.
References
Related entries
- Ampere AmpereOne AC03 before 3.5.9.3, AC04 before 4.4.5.2, AmpereOne M before 5.4.5.1CVE-2025-62863 · Ampere AmpereOne AC03 before 3.5.9.3, AC04 before 4.4.5.2, AmpereOne M before 5.4.5.1 - UEFI Management Mode PCIe…Critical
- Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range): The inline copy path adds a page index where itCVE-2025-68811 · Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range)Critical
- Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range): svc_rdma_copy_inline_range indexes rq_pages with anCVE-2025-71068 · Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range)Critical
- Linux RDMA/srpt: failed multi-buffer descriptor setup leaves stale counters and a dangling rw_ctxs pointerCVE-2026-100075 · Linux kernel RDMA/srpt (SRP target, srpt_alloc_rw_ctxs unwind)Critical
- Cisco Nexus 9000: unauthenticated remote code execution as root via Silicon One ports in the default L3 VRFCVE-2026-20212 · Cisco Nexus 9000 NX-OS Silicon One integration (S1HAL, TCP 43210/43211)Critical
- Linux kernel nvmet-tcp - PDU iovec construction and H2C Transfer Tag handling: nvmet_tcp_build_pdu_iovec() walks pastCVE-2026-23112 · Linux kernel nvmet-tcp - PDU iovec construction and H2C Transfer Tag handlingCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.