CVE-2026-64319 (GCVE-0-2026-64319)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (hash length) and dhvlen (DH value length) fields without verifying they fit within the allocated buffer of tl bytes. A malicious NVMe-oF initiator can craft a DHCHAP_REPLY message with a small transfer length but large hl/dhvlen values, causing out-of-bounds heap reads when the target processes the DH public key (rval + 2*hl) or performs the host response memcmp. With DH authentication configured, the OOB pointer is passed directly to sg_init_one() and read by crypto_kpp_compute_shared_secret(), reaching up to 526 bytes past the buffer. This is exploitable pre-authentication. Add bounds validation ensuring sizeof(*data) + 2*hl + dhvlen <= tl before any access to the variable-length fields. Discovered by Atuin - Automated Vulnerability Discovery Engine.
Impacted products
Vendor Product Version
Linux Linux Version: db1312dd95488b5e6ff362ff66fcf953a46b1821
Version: db1312dd95488b5e6ff362ff66fcf953a46b1821
Version: db1312dd95488b5e6ff362ff66fcf953a46b1821
Version: db1312dd95488b5e6ff362ff66fcf953a46b1821
Version: db1312dd95488b5e6ff362ff66fcf953a46b1821
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/nvme/target/fabrics-cmd-auth.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "80cd28b56ab62d3e7ed0a7bf05282e6d3ee5b2a0",
              "status": "affected",
              "version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
              "versionType": "git"
            },
            {
              "lessThan": "999f6205ede984a786f35f727b01f971b98e215d",
              "status": "affected",
              "version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
              "versionType": "git"
            },
            {
              "lessThan": "6d7649c1231dac14d906985d2936967e23041c26",
              "status": "affected",
              "version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
              "versionType": "git"
            },
            {
              "lessThan": "caa71b3a43ea5c13fe7141cb019ebcb03b8ac857",
              "status": "affected",
              "version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
              "versionType": "git"
            },
            {
              "lessThan": "3a413ece2504c70aa34a20be4dafec04e8c741f9",
              "status": "affected",
              "version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/nvme/target/fabrics-cmd-auth.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.0"
            },
            {
              "lessThan": "6.0",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.96",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.39",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.145",
                  "versionStartIncluding": "6.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.96",
                  "versionStartIncluding": "6.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.39",
                  "versionStartIncluding": "6.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.4",
                  "versionStartIncluding": "6.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "6.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-auth: validate reply message payload bounds against transfer length\n\nnvmet_auth_reply() accesses the variable-length rval[] array using\nattacker-controlled hl (hash length) and dhvlen (DH value length) fields\nwithout verifying they fit within the allocated buffer of tl bytes.\n\nA malicious NVMe-oF initiator can craft a DHCHAP_REPLY message with a\nsmall transfer length but large hl/dhvlen values, causing out-of-bounds\nheap reads when the target processes the DH public key (rval + 2*hl) or\nperforms the host response memcmp.\n\nWith DH authentication configured, the OOB pointer is passed directly to\nsg_init_one() and read by crypto_kpp_compute_shared_secret(), reaching\nup to 526 bytes past the buffer. This is exploitable pre-authentication.\n\nAdd bounds validation ensuring sizeof(*data) + 2*hl + dhvlen \u003c= tl before\nany access to the variable-length fields.\n\nDiscovered by Atuin - Automated Vulnerability Discovery Engine."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - A remote peer can send the malformed Authentication Send command over NVMe/TCP, which dispatches it through nvmet_req_init() and nvmet_parse_fabrics_admin_cmd() to nvmet_execute_auth_send() and nvmet_auth_reply().\nAC:L - The attacker drives the required Connect, Negotiate, Receive, and Reply sequence and controls the transfer length, hash length, DH length, and transaction ID. No race or condition outside the attacker\u0027s control is required.\nPR:N - The allowed Host NQN is an attacker-supplied protocol identifier rather than a credential, and the actual DH-HMAC-CHAP secret is not verified until after the vulnerable read. The path is therefore exploitable pre-authentication.\nUI:N - No victim action is required after the target service and authentication configuration are active; the remote initiator independently completes the protocol sequence.\nS:U - The vulnerable NVMe target code and the affected kernel memory and availability belong to the same host security authority, with no demonstrated VM, IOMMU, or sandbox boundary crossing.\nC:H - The attacker controls a substantial kernel heap over-read through memcmp and the crypto scatterlist/MPI path, with the input pointer reaching hundreds of bytes beyond the allocation and an attacker-selected read length. Adjacent kernel secrets and pointers are therefore at risk.\nI:N - All identified unsafe accesses are reads into correctly sized cryptographic output buffers. No out-of-bounds write, arbitrary modification, or defensible authentication bypass was found.\nA:H - The crypto/MPI over-read can traverse heap-object and page boundaries and fault in kernel context, causing an oops or panic that takes down the storage target or host. An unauthenticated peer can reconnect and trigger it repeatedly."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-17T04:53:19.887Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/80cd28b56ab62d3e7ed0a7bf05282e6d3ee5b2a0"
        },
        {
          "url": "https://git.kernel.org/stable/c/999f6205ede984a786f35f727b01f971b98e215d"
        },
        {
          "url": "https://git.kernel.org/stable/c/6d7649c1231dac14d906985d2936967e23041c26"
        },
        {
          "url": "https://git.kernel.org/stable/c/caa71b3a43ea5c13fe7141cb019ebcb03b8ac857"
        },
        {
          "url": "https://git.kernel.org/stable/c/3a413ece2504c70aa34a20be4dafec04e8c741f9"
        }
      ],
      "title": "nvmet-auth: validate reply message payload bounds against transfer length",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-64319",
    "datePublished": "2026-07-25T08:49:48.291Z",
    "dateReserved": "2026-07-19T15:36:31.780Z",
    "dateUpdated": "2026-08-17T04:53:19.887Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…