Database/Firmware, BMC & network fabric
Linux kernel NVMe-oF TCP target (nvmet-tcp, H2C_DATA PDU before CONNECT): Nvmet_tcp_build_pdu_iovec() dereferences cmd
Impact
Nvmet_tcp_build_pdu_iovec() dereferences cmd->req.sg and cmd->iov without checking they were ever initialised. Sending an H2C_DATA PDU straight after the ICREQ/ICRESP handshake - before any CONNECT command, before any NVMe-level identification of the initiator - reaches that dereference and crashes the target. This is genuinely pre-authentication: the only thing the attacker completes is the transport handshake, and the payoff is taking down the storage target for every tenant it serves.
Who can reach it
Remote, fully unauthenticated, immediately after TCP connect and the NVMe/TCP ICREQ exchange. No host NQN, no DH-HMAC-CHAP, nothing.
What to do
Kernel update adding the NULL checks before processing H2C_DATA. Because it is pre-auth, in-band authentication does not help you here - the compensating control is network reachability: the nvmet listener must not be reachable from tenant-routable networks, only from the storage fabric.
References
Related entries
- Linux kernel SoftiWARP receive path (siw_qp_rx, siw_tcp_rx_data header processing): When siw_get_hdr() rejects a headerCVE-2026-23242 · Linux kernel SoftiWARP receive path (siw_qp_rx, siw_tcp_rx_data header processing)High
- GNU FreeIPMI's ipmi-oem tool before version 1.6.17: The direction of trust is what makes this operator-relevantCVE-2026-33554 · GNU FreeIPMI's ipmi-oem tool before version 1.6.17High
- Cocos AI - attested TLS (aTLS) on AMD SEV-SNP and Intel TDX: The attested-TLS implementation is vulnerable to a relayCVE-2026-33697 · Cocos AI - attested TLS (aTLS) on AMD SEV-SNP and Intel TDXHigh
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When an XDP program shrinks a multi-fragment receive bufferCVE-2026-43464 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel - RDMA/rxe (Soft-RoCE) responder, drivers/infiniband/sw/rxe/rxe_resp.c: Atomic_write_reply() dereferencesCVE-2026-46114 · Linux kernel - RDMA/rxe (Soft-RoCE) responder, drivers/infiniband/sw/rxe/rxe_resp.cHigh
- Linux kernel - RDMA/rxe (Soft-RoCE) ICRC processing, drivers/infiniband/sw/rxe: The follow-up to CVE-2026-46043, andCVE-2026-46133 · Linux kernel - RDMA/rxe (Soft-RoCE) ICRC processing, drivers/infiniband/sw/rxeHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.