KernelScan.io

CRITICAL Introduced in 6.0

nvmet AuthNegotiate OOB

CVE-2026-90230

CVSS 9.1 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

KernelScan AI9.1CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with the host-supplied transfer length (tl) and hands it to nvmet_auth_negotiate() without passing tl along. nvmet_auth_negotiate() then reads the negotiate header and, for each of the halen hash identifiers and dhlen DH group identifiers, indexes into the fixed idlist[60] array (hashes at idlist[0..halen), groups at idlist[30..]). Neither the transfer length nor halen/dhlen is validated. A malicious or non-conformant host can report a tl smaller than the negotiate structure, or a halen/dhlen larger than the array (both are u8, up to 255), making the loops read past the end of the allocated buffer (heap out-of-bounds read). The sibling nvmet_auth_reply() already validates tl against the structure size; the negotiate path did not. Pass tl into nvmet_auth_negotiate(), reject a tl that does not cover the negotiate data plus one full protocol descriptor, and reject halen/dhlen larger than NVME_AUTH_DHCHAP_MAX_DH_IDS.

02

Engine v0.6.0

Risk summary

A remote, unauthenticated attacker connecting to an NVMe-oF target can send a malformed authentication negotiate message that causes the kernel to read past the end of a heap buffer, leaking kernel memory or crashing the system. The vulnerability is in the pre-authentication path, so no credentials are required. Any system running the NVMe-oF target with in-band authentication support compiled in is affected.

Affecteddrivers/nvme/target/fabrics-cmd-auth.c (nvmet)

Vulnerability analysis

The NVMe-oF target's in-band authentication negotiate handler reads hash and DH-group identifier lists from a buffer whose size is determined by the connecting host's reported transfer length, but it never validates that the buffer is large enough to hold the data it reads, nor that the identifier counts in the message header stay within the fixed-size lookup array. A remote host can send an authentication negotiate message with a transfer length smaller than the message structure, or with identifier counts exceeding the array bounds, causing the kernel to read arbitrarily past the end of the allocated heap buffer. The fix passes the transfer length into the negotiate handler, rejects messages too small to contain the required structure plus one protocol descriptor, and rejects identifier counts exceeding the defined maximums. Any network client that can reach an NVMe-oF target can trigger this without credentials, since the bug is in the pre-authentication negotiation step.

03

BranchIntroducedFixed inPatch commit
6.126.06.12.110aaac783950b1
6.186.06.18.52c38a81863267
mainline6.07.3-rc15bb96cc21883
7.26.07.2.67b81e4d2230e
6.66.06.6.15789ff11b72f38