SB20260816395 - Out-of-bounds read in Linux kernel nvme target driver
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-72129)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in nvmet_rdma_use_inline_sg() and inline scatterlist handling in the NVMe target RDMA component when processing host-controlled inline data with a nonzero offset. A remote user can send crafted inline data offsets and lengths to cause a denial of service.
The issue can be triggered when inline_data_size is configured larger than PAGE_SIZE, and page-spanning in-bounds ranges may also cause the scatterlist to be under-counted.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/11401371152b228448a41d79c6de1c938f93049a
- https://git.kernel.org/stable/c/2944113ad5fbcdf5d349d857c03d2a44b6de75b8
- https://git.kernel.org/stable/c/42a8ea3acd883f4f210d9e54e0975b1e2292b529
- https://git.kernel.org/stable/c/48c0162f647bb47e6084ffbc71b8f213f5e2f4f8
- https://git.kernel.org/stable/c/7c96581169c9d9a7d0726e554313acfbead6141c
- https://git.kernel.org/stable/c/98bcdfa619150b2f41fa15bac140dbaf2584ad05
- https://git.kernel.org/stable/c/bf8bcc1c137d54a62a428b00051fdbb13660673b
- https://git.kernel.org/stable/c/c2106ba1b14d644a5203bea1a50dbe25dcad713c