GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel NVMe driver (FDP configurations log parsing): While walking the Flexible Data Placement configurations

CVSS 8.2CVE-2026-97433Kernel, userspace & hypervisorcurated

Impact

While walking the Flexible Data Placement configurations log, the driver did not validate descriptor sizes, so a descriptor with dsze == 0 or one that extends past the end of the log causes an infinite loop or reads beyond the buffer. The input comes from the storage device, which means the exposure is a malfunctioning or hostile NVMe controller - most realistically an NVMe-oF target rather than a soldered-in local drive. On a GPU node the practical outcome is a hung or crashing kernel thread during device probe, taking the node and its jobs out of service; the NVD vector claims a network attack path, which fits the fabric-attached case and not a local disk. No code execution is claimed in the commit.

Who can reach it

Whoever controls the NVMe controller's responses: an NVMe-oF target or a device on the storage fabric that the node attaches. Not reachable from an unprivileged tenant process on the node.

What to do

Take the stable kernel containing the linked commits and reboot each node on it - a node drain and reboot per host, which on GPU fleets means draining running jobs. There is no runtime mitigation short of not attaching untrusted NVMe-oF targets; keep the storage fabric on a network only the operator controls.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.