CVE-2026-52989: falha crítica em Linux
nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers
Publicada em · Atualizada em
28Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 9.8epss 0.5%
probabilidade de exploração
0.5%top 58% das CVEs
exploração observada
nãonenhuma fonte reporta
In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers
Currently, when nvmet_tcp_build_pdu_iovec() detects an out-of-bounds
PDU length or offset, it triggers nvmet_tcp_fatal_error(cmd->queue)
and returns early. However, because the function returns void, the
callers are entirely unaware that a fatal error has occurred and
that the cmd->recv_msg.msg_iter was left uninitialized.
Callers such as nvmet_tcp_handle_h2c_data_pdu() proceed to blindly
overwrite the queue state with queue->rcv_state = NVMET_TCP_RECV_DATA
Consequently, the socket receiving loop may attempt to read incoming
network data into the uninitialized iterator.
Fix this by shifting the error handling responsibility to the callers.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Linux · LinuxCVEs relacionadas — Linux
No mesmo produto, das mais perigosas para as menos.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
Referências
https://access.redhat.com/security/cve/CVE-2026-52989https://bugzilla.redhat.com/show_bug.cgi?id=2492443https://git.kernel.org/stable/c/046fa5c72d15cd8e2d592e275697ea399d8f76b0https://git.kernel.org/stable/c/3df42a854686fa06484e37ac1a3931c8e3e3453chttps://git.kernel.org/stable/c/c2a11441538bdbbc5aa003f190995eba93a89b88https://git.kernel.org/stable/c/d7c8f95f599b3b38a717d2e771c3f8c174f657c3https://git.kernel.org/stable/c/ea8e356acb165cb1fd75537a52e1f66e5e76c538https://git.kernel.org/stable/c/f9204a2b78dd18374d3bcf9bf93d9021ce22de1bhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52989.json