Improper Enforcement of Behavioral Workflow in Linux kernel - CVE-2026-89968
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of protocol state in nvmet_tcp_handle_h2c_data_pdu() when processing an unsolicited H2CData PDU before transmitting a requested data transfer (R2T). A remote attacker can send an H2CData PDU for a write command before the R2T is transmitted to cause a denial of service.
The affected subsystem must be configured with allow_any_host.
Affected software
How to mitigate CVE-2026-89968
External References
- https://git.kernel.org/stable/c/02341ee424fb2eed16b5b8a9d247492e49335c21
- https://git.kernel.org/stable/c/14beef7d4f123fb458fc9844aa74a071871dcca6
- https://git.kernel.org/stable/c/1cbed7538946c99e585acefd11c9ba3a0bdbae05
- https://git.kernel.org/stable/c/2b71f9193e3d3a352920ba367f1a6db345249038
- https://git.kernel.org/stable/c/9fb527103e53fd43a8e802c2eca407869c204f7a
- https://git.kernel.org/stable/c/cade124c06f8e738e3a0df285ed2e08953e6bfaa
- https://git.kernel.org/stable/c/cf1484d9a75de6809ef331e16f525aaa41b0e16d
- https://git.kernel.org/stable/c/db62b35cbca052860c519cbcabe7650708528738