Database/Kernel, userspace & hypervisor
Linux kernel NVMe driver (FDP configurations log parsing): While walking the Flexible Data Placement configurations
Impact
While walking the Flexible Data Placement configurations log, the driver did not validate descriptor sizes, so a descriptor with dsze == 0 or one that extends past the end of the log causes an infinite loop or reads beyond the buffer. The input comes from the storage device, which means the exposure is a malfunctioning or hostile NVMe controller - most realistically an NVMe-oF target rather than a soldered-in local drive. On a GPU node the practical outcome is a hung or crashing kernel thread during device probe, taking the node and its jobs out of service; the NVD vector claims a network attack path, which fits the fabric-attached case and not a local disk. No code execution is claimed in the commit.
Who can reach it
Whoever controls the NVMe controller's responses: an NVMe-oF target or a device on the storage fabric that the node attaches. Not reachable from an unprivileged tenant process on the node.
What to do
Take the stable kernel containing the linked commits and reboot each node on it - a node drain and reboot per host, which on GPU fleets means draining running jobs. There is no runtime mitigation short of not attaching untrusted NVMe-oF targets; keep the storage fabric on a network only the operator controls.
References
Related entries
- Linux kernel x86/mm/pat: split page tables bypass kernel page table tracking, leaving stale IOTLB entries after freeCVE-2026-97525 · Linux kernel x86 CPA/PAT (__split_large_page kernel page table allocation)High
- Linux kernel (net/tls): When a NIC with active kTLS offload goes down, the offload teardown freed the TLS context whileCVE-2021-47131 · Linux kernel (net/tls)High
- VMware ESXi / Workstation / Fusion (storage controller out-of-bounds read/write): A malicious actor inside a VMCVE-2024-22273 · VMware ESXi / Workstation / Fusion (storage controller out-of-bounds read/write)High
- Linux kernel (net/xfrm): The error path of xfrm_input leaves the secpath entry pointing at poisoned memory, and theCVE-2024-43878 · Linux kernel (net/xfrm)High
- Linux kernel NVMe target authentication (nvmet-auth DH group setup): CtrlCVE-2024-50215 · Linux kernel NVMe target authentication (nvmet-auth DH group setup)High
- OpenSSH (sshd): regreSSHion: signal-handler race in sshd giving unauthenticated remote root on glibc LinuxCVE-2024-6387 · OpenSSH (sshd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.