Database/Kernel, userspace & hypervisor
Linux kernel NVMe-oF TCP target (nvmet-tcp, data-digest mismatch handling): With data digests enabled, a digest
Impact
With data digests enabled, a digest mismatch on a non-final H2C_DATA PDU makes the error handler call nvmet_req_uninit() - dropping the submission-queue percpu reference - without marking the command completed. Queue teardown then walks the command list, still sees the command as needing data, and touches it again: use-after-free on the storage target that serves the cluster's datasets and checkpoints. The attacker only needs to be able to open an NVMe/TCP connection and send a bad digest, so this is unauthenticated remote memory corruption in the process that has every tenant's namespaces attached.
Who can reach it
Remote and unauthenticated. Any host that can reach the nvmet-tcp listener - and on most clusters the storage VLAN is reachable from compute nodes, which means from tenant containers with host networking or from a compromised co-tenant job.
What to do
Kernel update on the storage target nodes making the digest-error path mark the command completed. Interim controls that actually work: turn off data digests on the affected subsystems (removes the trigger), and restrict the nvmet listener to the storage network with an explicit host-NQN allow list rather than accepting any connecting initiator.
References
Related entries
- Linux kernel SMC-R connection data control (smc_cdc_rx_handler socket lifetime): The CDC receive handler looks theCVE-2026-64541 · Linux kernel SMC-R connection data control (smc_cdc_rx_handler socket lifetime)Critical
- Linux kernel (net/xfrm): The same ownership-marker bug as CVE-2026-53363, in the other IPTFS frag-transfer helper.CVE-2026-64566 · Linux kernel (net/xfrm)Critical
- Linux kernel libceph: malicious OSD triggers out-of-bounds reads in RBD lock-info decodeCVE-2026-68082 · Linux kernel libceph (decode_lockers() in cls_lock_client.c)Critical
- Linux libceph: CRUSH map with a zero bucket type makes the mapper index the OSD weight array negativelyCVE-2026-68154 · Linux kernel libceph (crush_decode, CRUSH map bucket type validation)Critical
- Linux libceph: stale authorizer buffer pointer after ticket refresh causes a use-after-free on msgr1 reconnectCVE-2026-68156 · Linux kernel libceph (ceph_x authorizer buffer, ceph_auth_handshake stale pointer)Critical
- Linux libceph: integer overflow in osdmap decoding defeats the bounds check and reads out of boundsCVE-2026-68158 · Linux kernel libceph (decode_new_up_state_weight, osdmap length arithmetic)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.