SB20260916144 - Out-of-bounds write in Linux kernel nvme target driver
Published: September 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-89969)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an out-of-bounds write in nvmet_tcp_try_recv_pdu() when receiving an over-long NVMe/TCP PDU. A remote attacker can send a duplicate ICReq PDU after header digest negotiation to execute arbitrary code.
The attacker-controlled overflow can overwrite the adjacent header and data digest fields before the duplicate ICReq is rejected.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/14cc5a7e77731497d5bea70f3bb05df7eda982e4
- https://git.kernel.org/stable/c/3a385e0c39efbe34db8edd95900c123113ae3450
- https://git.kernel.org/stable/c/4f84d42c53c49557fb1ef285c683b0a81b576c74
- https://git.kernel.org/stable/c/58dc6035b79c4c73c0cbf9ec9f68a7f117b2b3e6
- https://git.kernel.org/stable/c/a3f0bcfbaf3312a5754d1ce020a07d394669eb25
- https://git.kernel.org/stable/c/cf5f39d2b58f97e0cd1829c4a6aeef17f1607cca
- https://git.kernel.org/stable/c/d95d342bc0ea82dc79e6362b2f1f997431750e4c
- https://git.kernel.org/stable/c/dbc4acbdb3ca8c81441368ad7409b8f77d4de8f6