CVE-2026-90230

Source
https://cve.org/CVERecord?id=CVE-2026-90230
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90230.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90230
Downstream
Published
2026-09-17T16:07:37Z
Modified
2026-09-20T11:30:50Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
Details

In the Linux kernel, the following vulnerability has been resolved:

nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()

nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with the host-supplied transfer length (tl) and hands it to nvmet_auth_negotiate() without passing tl along. nvmet_auth_negotiate() then reads the negotiate header and, for each of the halen hash identifiers and dhlen DH group identifiers, indexes into the fixed idlist[60] array (hashes at idlist[0..halen), groups at idlist[30..]).

Neither the transfer length nor halen/dhlen is validated. A malicious or non-conformant host can report a tl smaller than the negotiate structure, or a halen/dhlen larger than the array (both are u8, up to 255), making the loops read past the end of the allocated buffer (heap out-of-bounds read). The sibling nvmet_auth_reply() already validates tl against the structure size; the negotiate path did not.

Pass tl into nvmet_auth_negotiate(), reject a tl that does not cover the negotiate data plus one full protocol descriptor, and reject halen/dhlen larger than NVME_AUTH_DHCHAP_MAX_DH_IDS.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90230.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
db1312dd95488b5e6ff362ff66fcf953a46b1821
Fixed
89ff11b72f38976f3b5aea23a5228ee05e277209
Fixed
aaac783950b17c57df9b6f7344747cacb1a407ed
Fixed
c38a8186326799957d293d370136c128cd113916
Fixed
7b81e4d2230e3d2d372c826180c4ef0efc244f31
Fixed
5bb96cc218835769ab74ec7f3ea2bf81fbffe955

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90230.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90230.json"