CRITICAL Introduced in 6.0
nvmet-auth AuthReceive OOB Write
CVE-2026-72130
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI9.8CRITICAL
01Description
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: reject short AUTH_RECEIVE buffers nvmet_execute_auth_receive() trusts the AUTH_RECEIVE allocation length after checking only that it is nonzero and matches the transfer length. In the SUCCESS1 and FAILURE1/default states, that lets a remote NVMe-oF initiator reach the fixed-size DH-HMAC-CHAP response builders with a kmalloc() buffer shorter than the response, so nvmet_auth_success1() and nvmet_auth_failure1() write past the allocation; both only WARN_ON the short length and then format the message anyway. Impact: A remote NVMe-oF initiator with access to an auth-enabled target can trigger a 16-byte heap out-of-bounds write via a one-byte AUTH_RECEIVE allocation length. Compute the minimum response length for the current DH-HMAC-CHAP step in nvmet_auth_receive_data_len() and report a zero data length when the host-supplied allocation length is shorter, so the existing zero-length check in nvmet_execute_auth_receive() rejects the command before any builder runs. The SUCCESS1 minimum is sizeof(struct nvmf_auth_dhchap_success1_data) plus the HMAC hash length, because the response hash is written into the rval[] flexible-array tail, so the minimum is state dependent rather than a flat sizeof. CHALLENGE keeps its existing variable-length guard in nvmet_auth_challenge(). This is reachable only when in-band DH-HMAC-CHAP authentication is configured on the target.
02KernelScan AI Analysis
Risk summary
A remote NVMe-oF initiator with access to an auth-enabled target can trigger a 16-byte heap out-of-bounds write via a one-byte AUTH_RECEIVE allocation length. The bug is reachable only when in-band DH-HMAC-CHAP authentication is configured on the target.
Vulnerability analysis
The NVMe-oF target authentication receive handler trusts the initiator-supplied allocation length without verifying it is large enough for the fixed-size DH-HMAC-CHAP response that will be formatted into it. In the SUCCESS1 and FAILURE1 states, the response builders only warn on a short buffer and then write the full response header and HMAC hash past the end of the undersized kernel allocation, producing a heap out-of-bounds write. The fix computes the minimum response length for the current authentication step and reports zero data length when the supplied allocation is shorter, so the existing zero-length check rejects the command before any builder runs. A remote NVMe-oF initiator that can reach an auth-enabled target can trigger this with no privileges beyond network connectivity.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.18 | 6.0 | 6.18.40 | 2eaa3ad45014 |
| mainline | 6.0 | 7.2-rc1 | 779575bc35c6 |
| 6.12 | 6.0 | 6.12.101 | 80bf7b7f676e |
| 7.1 | 6.0 | 7.1.5 | bc111698b46e |