SB20260905159 - Release of invalid pointer or reference in Linux kernel nvme target driver
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Release of invalid pointer or reference (CVE-ID: CVE-2026-80790)
CWE-ID: CWE-763 - Release of invalid pointer or reference
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger an invalid memory free.
The vulnerability exists due to improper pointer handling in nvmet_fc_alloc_ls_iodlist() when handling request-buffer allocation or response-buffer DMA mapping failures while initializing the LS IOD array. A local user can create a target port under these failure conditions to trigger an invalid memory free.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1a8f007faefe8c226ec65896589f8d59b0a8d5a5
- https://git.kernel.org/stable/c/371fb1bf902adaa59be32bd7e904a5317e604fd0
- https://git.kernel.org/stable/c/449e9c4f8db84ad9d9bb288029b230bcf590faa2
- https://git.kernel.org/stable/c/8bce9cd08aae4283badf8ddc11fbb6f57b75a81e
- https://git.kernel.org/stable/c/94334ea92f4d7535f66f86e33681efa94827eddc
- https://git.kernel.org/stable/c/b189c6e408896ccc23d2e76d7738847cdebf1532
- https://git.kernel.org/stable/c/ba98d6796d12258e837ece065d2ecb59d76ce4ff
- https://git.kernel.org/stable/c/bb9489f0dce58da730d3479588d6710d7a2c1b45
- https://git.kernel.org/stable/c/d094582cce9c08516d714e7436a8f3b9211dda90