KernelScan.io

CRITICAL Introduced in 6.19

nvmet-tcp PDUiovec UninitRead

CVE-2026-52989

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI9.6CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers Currently, when nvmet_tcp_build_pdu_iovec() detects an out-of-bounds PDU length or offset, it triggers nvmet_tcp_fatal_error(cmd->queue) and returns early. However, because the function returns void, the callers are entirely unaware that a fatal error has occurred and that the cmd->recv_msg.msg_iter was left uninitialized. Callers such as nvmet_tcp_handle_h2c_data_pdu() proceed to blindly overwrite the queue state with queue->rcv_state = NVMET_TCP_RECV_DATA Consequently, the socket receiving loop may attempt to read incoming network data into the uninitialized iterator. Fix this by shifting the error handling responsibility to the callers.

02

Engine v0.3.0

Risk summary

A remote NVMe-over-TCP initiator can send a malformed H2C data PDU with an out-of-bounds length or offset, causing the target kernel to use an uninitialized msg_iter when reading subsequent network data. This leads to kernel memory corruption and a kernel panic. Any system running the NVMe-oF TCP target (nvmet-tcp) and accepting connections from untrusted initiators is at risk.

Affecteddrivers/nvme/target/tcp.c (NVMe-oF TCP target driver)

Vulnerability analysis

The root cause is that nvmet_tcp_build_pdu_iovec() was declared void and, upon detecting an out-of-bounds PDU length or offset, called nvmet_tcp_fatal_error() and returned early without initializing cmd->recv_msg.msg_iter. Because the function returned void, callers such as nvmet_tcp_handle_h2c_data_pdu() and nvmet_tcp_done_recv_pdu() had no way to detect the error and proceeded to set queue->rcv_state = NVMET_TCP_RECV_DATA. The socket receive loop then used the uninitialized iterator as a destination for incoming network data, causing writes to garbage kernel addresses. The fix changes nvmet_tcp_build_pdu_iovec() to return an int error code (-EPROTO) and updates all callers to check the return value and abort the command, ensuring the uninitialized iterator is never used. The attack surface is the NVMe-oF TCP target listener socket, reachable from the network without authentication at the PDU parsing layer.

03

BranchIntroducedFixed inPatch commit
6.16.1.1636.1.1753df42a854686
6.126.12.706.12.91f9204a2b78dd
6.186.18.106.18.33c2a11441538b
7.06.197.0.10—
mainline6.197.1—
6.66.6.1246.6.141d7c8f95f599b
5.105.10.2505.11046fa5c72d15
5.155.15.2005.16ea8e356acb16