In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
When fuzzing the nvme target code, I tripped a kernel warning in nvmettcpmap_data() because the length passed into the allocator is controlled by the remote initiator.
A remote initiator that sends a command with an SGL claiming a huge number, can create a scatterlist and iovec allocation of over 1 million entries, which causes the backing kmalloc call to exceed MAXPAGEORDER and then the page allocator will trip on a WARNONONCE_GFP() message:
WARNING: mm/page_alloc.c:5280 _allocfrozenpagesnoprof Workqueue: nvmettcpwq nvmettcpiowork ... sglallocorder nvmettcpmapdata nvmettcptryrecvpdu
As it's never good to trip a kernel warning remotely due to many systems having panic-on-warn enabled, let's silence it by just add GFP_NOWARN to the allocation flags.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80788.json",
"cna_assigner": "Linux"
}