Database/Kernel, userspace & hypervisor
Linux kernel (drivers/nvme/host): An off-by-one in the Flexible Data Placement index check accepts a placement index
Impact
An off-by-one in the Flexible Data Placement index check accepts a placement index one past the end of the configuration array, so a value that came from userspace is used to read out of bounds in the I/O submission path. The tenant supplying the index gets an out-of-bounds read of adjacent kernel memory and, at minimum, a node-destabilising fault.
Who can reach it
Reachable by an unprivileged process on the node that can issue I/O to an FDP-capable NVMe namespace and set the write placement hint - no /dev/nvme passthrough or CAP_SYS_ADMIN needed, since the placement index rides on ordinary writes. Conditional on the namespace having FDP enabled, which is increasingly common on modern datacenter SSDs used for tenant scratch space.
What to do
No fixed version is listed on this record - boot a kernel carrying the linked stable commits. Interim: disable FDP on namespaces exposed to tenants, or do not hand tenants direct block devices on FDP-enabled drives until the node is patched.
References
Related entries
- Linux kernel (drivers/nvme/host): The multipath current-path array is sized by the count of possible NUMA nodes butCVE-2026-74384 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): The PRP list mempool is sized in the wrong units, so a large I/O that needs two PRPCVE-2022-50756 · Linux kernel (drivers/nvme/host)High
- Linux kernel (drivers/nvme/host): The NVMe/RDMA initiator destroys the queue pair before the connection manager ID, soCVE-2021-47378 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): On the NVMe/RDMA initiator, an async-event command can be submitted against an adminCVE-2022-48788 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): Same race as the RDMA variant but on NVMe/TCP, which is the far more common fabric inCVE-2022-48789 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): The multipath sibling list is walked without SRCU protection during path revalidationCVE-2022-49003 · Linux kernel (drivers/nvme/host)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.