Database/Firmware, BMC & network fabric
Linux kernel NVMe-oF TCP target (nvmet-tcp, unpropagated PDU iovec build errors): Nvmet_tcp_build_pdu_iovec() detects
Impact
Nvmet_tcp_build_pdu_iovec() detects an out-of-bounds PDU length or offset, flags a fatal error - and returns void. The caller never learns, sets the queue into receive-data state anyway, and the socket loop then reads attacker-supplied network bytes into an uninitialised iov_iter. A remote initiator that sends a malformed PDU length therefore steers kernel writes through an iterator whose contents are whatever was on the stack. The kernel CNA rates it network, unauthenticated, full CIA, and the reasoning is visible in the fix.
Who can reach it
Remote, unauthenticated, by sending a PDU with an out-of-range length or data offset to the nvmet-tcp listener.
What to do
Kernel update making the iovec builder return an error and the callers honour it. Same network containment applies: the storage target's listener must be unreachable from tenant networks.
References
Related entries
- Linux kernel - iSER (iSCSI Extensions for RDMA) target, drivers/infiniband/ulp/isert/ib_isert.c: The iSER targetCVE-2026-53176 · Linux kernel - iSER (iSCSI Extensions for RDMA) target, drivers/infiniband/ulp/isert/ib_isert.cCritical
- uefi-firmware-parser: unvalidated bit lengths in MakeTable() smash the stack on crafted firmwareCVE-2026-54333 · uefi-firmware-parser Tiano decompressor (MakeTable bit-length validation)Critical
- uefi-firmware-parser: ReadCLen() overruns the 510-entry mCLen heap array on crafted firmwareCVE-2026-54334 · uefi-firmware-parser Tiano decompressor (ReadCLen mCLen bounds)Critical
- Dell SmartFabric OS10 before 10.6.1.3: session fixation lets a remote unauthenticated attacker steal a sessionCVE-2026-63695 · Dell SmartFabric OS10 (session handling in the management interface)Critical
- Linux kernel (drivers/infiniband/ulp/rtrs): On the RTRS server, a failure while publishing a new session's sysfsCVE-2026-64033 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
- Linux kernel - RDMA/siw (soft-iWARP) MPA framing, drivers/infiniband/sw/siw/siw_qp_rx.c: The siw receive path decodesCVE-2026-64102 · Linux kernel - RDMA/siw (soft-iWARP) MPA framing, drivers/infiniband/sw/siw/siw_qp_rx.cCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.