Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89482

nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
Back to all
CVE

CVE-2026-89482

nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone

In the Linux kernel, the following vulnerability has been resolved:

nvme-tcp: do not accept C2HData based on blkrqpayload_bytes() alone

Commit 25e5cb780e62 ("nvme-tcp: fix possible crash in write_zeroes

processing") established that blkrqpayload_bytes() must not be read

without first checking blkrqnrphyssegments(), and recorded the

result in nvmetcpsetupcmdpdu() as req->data_len. The receive side

was left as it was.

The two differ for REQOPWRITE_ZEROES, which has no physical segments

but a non-zero blkrqbytes(), so setup leaves req->iter untouched

while the receive gate lets a C2HData through and nvmetcprecv_data()

copies into whatever the previous command on that tag left there. The

driver-private area is zeroed only when the tag set is allocated.

Reproduced with a test target that leaves a residual iterator on a tag

and then sends a C2HData for a WRITE_ZEROES command on the same tag:

BUG: KASAN: wild-memory-access in copyto_iter+0x642/0x1330

Write of size 512 at addr ffe728c2175dfa81 by task kworker/0:1H/103

CPU: 0 UID: 0 PID: 103 Comm: kworker/0:1H Not tainted 7.2.0-rc5-NVMETCP-gf5098b6bae76 #1 PREEMPT(lazy)

Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014

Workqueue: nvmetcpwq nvmetcpio_work

Call Trace:

 <TASK>

 dumpstacklvl+0x53/0x70

 kasan_report+0xce/0x100

 ? copyto_iter+0x642/0x1330

 kasancheckrange+0x105/0x1b0

 _asanmemcpy+0x3c/0x60

 copyto_iter+0x642/0x1330

 ? _pfxsockhasperm+0x10/0x10

 ? worker_thread+0x45b/0xd10

 ? pfxcopytoiter+0x10/0x10

 ? rawspinlockbh+0x83/0xe0

 ? pfxrawspinlock_bh+0x10/0x10

 _skbdatagram_iter+0xf3/0x820

 ? _pfxsimplecopyto_iter+0x10/0x10

 ? _asanmemcpy+0x3c/0x60

 ? skbcopybits+0x58d/0x830

 skbcopydatagram_iter+0x37/0x120

 nvmetcprecv_skb+0xa07/0x4320

 ? _pfxnvmetcprecv_skb+0x10/0x10

 _tcpread_sock+0x1ab/0x810

 ? _pfxnvmetcprecv_skb+0x10/0x10

 ? _pfxlocksocknested+0x10/0x10

 ? pfxtcpread_sock+0x10/0x10

 nvmetcptry_recv+0x152/0x1e0

 ? _pfxnvmetcptry_recv+0x10/0x10

 ? _pfxmutex_unlock+0x10/0x10

 nvmetcpio_work+0x1e4/0x6c0

 ? __schedule+0x181a/0x49f0

 ? _pfxnvmetcpio_work+0x10/0x10

 processonework+0x633/0x1030

Keep the blkrqpayloadbytes() test and add req->datalen to it. The

old test is what rejects a C2HData naming a tag that is no longer in

flight, because blkupdaterequest() zeroes rq->_datalen on

completion; req->datalen and req->currbio are driver-private and

survive completion, so they cannot stand in for it. Setup initialises

the iterator only when both req->currbio and req->datalen are set, so

the gate now tests the same two.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/32ea8ce96b9bd797c59c351ce490ffd97adaa8c0, https://git.kernel.org/stable/c/3a4aa9e6ad3e35f8e24d5eaf38ee4d437075fb36, https://git.kernel.org/stable/c/641ad3a30ba560f0a9a610376c568d7b75d2a2aa, https://git.kernel.org/stable/c/6a01b58263108eaf9869bb6f82f07709240c6589, https://git.kernel.org/stable/c/7ed0b61bbc145988be292c4d3ec580aebd8d2bcd, https://git.kernel.org/stable/c/b36161701cb366f416afdcf70771d432a7c74753, https://git.kernel.org/stable/c/b96e1ff75e5c0ad6e077ac002b1d30b0a2b49528, https://git.kernel.org/stable/c/dd8906bb8f8d5bf1c9f861e1382c82b87bfe7cab, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89482.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89482, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00714%
EPSS Percentile
0.52229%
Introduced Version
25e5cb780e62bde432b401f312bb847edc78b432,5.4.36,5.6.8,f507ae6e33cbe56c4e3fe000434fc0ecc263d098,b1458c16f4e26e87492e58e4d24a1873bd09232a,5.7.0,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
3a4aa9e6ad3e35f8e24d5eaf38ee4d437075fb36,5.5,5.7,5.10.270,5.15.221,6.1.188,6.6.157,6.12.109,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading