← Back to search

CVE-2026-90230

9.1 CRITICAL

Published 2026-09-17 · Updated 2026-09-18

AI risk analysis

Summary
The flaw allows a malicious host to perform a heap out-of-bounds read by misreporting the transfer length or hash/dh group identifiers, potentially leading to information disclosure.
Exploitability
Exploitation is moderately difficult requiring a non-conformant host with control over the transfer length or hash/dh group identifiers.
Blast radius
If exploited, the vulnerability could lead to sensitive information disclosure, impacting system security and integrity.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the Linux kernel version 6.1.17 or later.
heap-overflowinformation-disclosurekernellinux

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with the host-supplied transfer length (tl) and hands it to nvmet_auth_negotiate() without passing tl along. nvmet_auth_negotiate() then reads the negotiate header and, for each of the halen hash identifiers and dhlen DH group identifiers, indexes into the fixed idlist[60] array (hashes at idlist[0..halen), groups at idlist[30..]). Neither the transfer length nor halen/dhlen is validated. A malicious or non-conformant host can report a tl smaller than the negotiate structure, or a halen/dhlen larger than the array (both are u8, up to 255), making the loops read past the end of the allocated buffer (heap out-of-bounds read). The sibling nvmet_auth_reply() already validates tl against the structure size; the negotiate path did not. Pass tl into nvmet_auth_negotiate(), reject a tl that does not cover the negotiate data plus one full protocol descriptor, and reject halen/dhlen larger than NVME_AUTH_DHCHAP_MAX_DH_IDS.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.