KernelScan.io

CRITICAL Introduced in 6.0

nvmet-auth AuthReceive OOB Write

CVE-2026-72130

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI9.8CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: reject short AUTH_RECEIVE buffers nvmet_execute_auth_receive() trusts the AUTH_RECEIVE allocation length after checking only that it is nonzero and matches the transfer length. In the SUCCESS1 and FAILURE1/default states, that lets a remote NVMe-oF initiator reach the fixed-size DH-HMAC-CHAP response builders with a kmalloc() buffer shorter than the response, so nvmet_auth_success1() and nvmet_auth_failure1() write past the allocation; both only WARN_ON the short length and then format the message anyway. Impact: A remote NVMe-oF initiator with access to an auth-enabled target can trigger a 16-byte heap out-of-bounds write via a one-byte AUTH_RECEIVE allocation length. Compute the minimum response length for the current DH-HMAC-CHAP step in nvmet_auth_receive_data_len() and report a zero data length when the host-supplied allocation length is shorter, so the existing zero-length check in nvmet_execute_auth_receive() rejects the command before any builder runs. The SUCCESS1 minimum is sizeof(struct nvmf_auth_dhchap_success1_data) plus the HMAC hash length, because the response hash is written into the rval[] flexible-array tail, so the minimum is state dependent rather than a flat sizeof. CHALLENGE keeps its existing variable-length guard in nvmet_auth_challenge(). This is reachable only when in-band DH-HMAC-CHAP authentication is configured on the target.

02

Engine v0.6.0

Risk summary

A remote NVMe-oF initiator with access to an auth-enabled target can trigger a 16-byte heap out-of-bounds write via a one-byte AUTH_RECEIVE allocation length. The bug is reachable only when in-band DH-HMAC-CHAP authentication is configured on the target.

Affecteddrivers/nvme/target/fabrics-cmd-auth.c (nvmet-auth)

Vulnerability analysis

The NVMe-oF target authentication receive handler trusts the initiator-supplied allocation length without verifying it is large enough for the fixed-size DH-HMAC-CHAP response that will be formatted into it. In the SUCCESS1 and FAILURE1 states, the response builders only warn on a short buffer and then write the full response header and HMAC hash past the end of the undersized kernel allocation, producing a heap out-of-bounds write. The fix computes the minimum response length for the current authentication step and reports zero data length when the supplied allocation is shorter, so the existing zero-length check rejects the command before any builder runs. A remote NVMe-oF initiator that can reach an auth-enabled target can trigger this with no privileges beyond network connectivity.

03

BranchIntroducedFixed inPatch commit
6.186.06.18.402eaa3ad45014
mainline6.07.2-rc1779575bc35c6
6.126.06.12.10180bf7b7f676e
7.16.07.1.5bc111698b46e