CRITICAL Introduced in 4.19
nvmet-rdma InlineSGL OOB
CVE-2026-72129
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI9.3CRITICAL
01Description
In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: handle inline data with a nonzero offset nvmet_rdma_use_inline_sg() maps the host-controlled inline data offset into the per-command inline scatterlist. The bounds check admits any offset with off + len <= inline_data_size, but the mapping still assumes the data begins in the first inline page: sg->offset = off; sg->length = min_t(int, len, PAGE_SIZE - off); When a port is configured with inline_data_size > PAGE_SIZE (settable up to max(SZ_16K, PAGE_SIZE)), an offset in (PAGE_SIZE, inline_data_size] makes "PAGE_SIZE - off" underflow, so sg->length is set to ~4 GiB and the block backend reads far past the first inline page. num_pages(len) also ignores the offset, so an in-bounds offset whose [off, off+len) span crosses a page boundary under-counts the scatterlist. Map the offset properly: split it into a page index and an in-page offset, start the scatterlist at that page, and size the page count from page_off + len. Because the request scatterlist may now start at inline_sg[page_idx] rather than inline_sg[0], generalize the inline-SGL identity test in nvmet_rdma_release_rsp() to a range test; otherwise the persistent inline scatterlist is mistaken for an allocated one and nvmet_req_free_sgls() frees an inline page (and warns in free_large_kmalloc()).
02KernelScan AI Analysis
Risk summary
A remote NVMe-oF RDMA client can send a command with a crafted inline data offset that causes the target kernel to read roughly four gigabytes past the allocated inline buffer, leaking kernel memory and likely crashing the system. The bug requires the target port to be configured with inline_data_size larger than PAGE_SIZE, which is possible on systems with 4 KB pages. Any device exposing an NVMe-oF RDMA target with that configuration is at risk from an unauthenticated network attacker.
Vulnerability analysis
The NVMe-oF RDMA target incorrectly maps a host-controlled inline data offset into its per-command scatterlist. When the target is configured with inline data larger than a page, a remote client can send a command whose inline data offset exceeds the page size, causing an arithmetic underflow that sets the scatterlist entry length to roughly four gigabytes. The block backend then reads far past the allocated inline buffer, leaking kernel memory and potentially crashing the system. A secondary miscalculation also under-counts the scatterlist page count when a valid offset crosses a page boundary. The fix decomposes the offset into a page index and in-page offset, starts the scatterlist at the correct page, and sizes the entry count properly; it also updates the release path to recognize scatterlists that no longer start at the first inline page. A remote NVMe-oF client can trigger this without authentication when the target port is configured with an inline data size larger than the system's page size, which is possible on systems with 4 KB pages.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.1 | 4.19 | 6.1.178 | 11401371152b |
| 6.12 | 4.19 | 6.12.97 | 42a8ea3acd88 |
| 6.18 | 4.19 | 6.18.40 | 2944113ad5fb |
| 7.1 | 4.19 | 7.1.5 | 98bcdfa61915 |
| mainline | 4.19 | 7.2-rc1 | 48c0162f647b |
| 6.6 | 4.19 | 6.6.145 | 7c96581169c9 |
| 5.15 | 4.19 | 5.15.212 | bf8bcc1c137d |
| 5.10 | 4.19 | 5.10.261 | c2106ba1b14d |