SB20260905158 - Allocation of Resources Without Limits or Throttling in Linux kernel nvme target driver
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-80789)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource allocation in nvmet_tcp_map_data() when processing write commands containing non-inline transport SGL data-block descriptors. A remote attacker can submit a crafted NVMe/TCP command with an oversized SGL length to cause a denial of service.
For write commands, the target waits for host data after issuing an R2T response.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0952541b153e258b99d39cdb03ea6919fdeb41d0
- https://git.kernel.org/stable/c/14dbe37681a6a7e346fc147bb363ec7cca3180a0
- https://git.kernel.org/stable/c/25ad03d5c0e858c4b63f1e4b6d461d2af1b30b22
- https://git.kernel.org/stable/c/4a3f00262a044e8e15064b1a6860968bf0500bf4
- https://git.kernel.org/stable/c/6d27199ebe8cb223022150f74be13f154a964474
- https://git.kernel.org/stable/c/d2acc96c528d589f5827cfb90e8e9229dd9d8cb4
- https://git.kernel.org/stable/c/d895e66628f939edbb98608f6e033d3d39e6e546
- https://git.kernel.org/stable/c/f63e89a0310264264923f84406dea05fe752de62
- https://git.kernel.org/stable/c/f6e51b09cbaa5f6f6e6a3a9dafa666f76c37aab5