* CVE-2026-80862: nvme-tcp: fix usage of page_frag_cache
@ 2026-09-04 15:53 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-04 15:53 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
nvme-tcp: fix usage of page_frag_cache
nvme uses page_frag_cache to preallocate PDU for each preallocated request
of block device. Block devices are created in parallel threads,
consequently page_frag_cache is used in not thread-safe manner.
That leads to incorrect refcounting of backstore pages and premature free.
That can be catched by !sendpage_ok inside network stack:
WARNING: CPU: 7 PID: 467 at ../net/core/skbuff.c:6931 skb_splice_from_iter+0xfa/0x310.
tcp_sendmsg_locked+0x782/0xce0
tcp_sendmsg+0x27/0x40
sock_sendmsg+0x8b/0xa0
nvme_tcp_try_send_cmd_pdu+0x149/0x2a0
Then random panic may occur.
Fix that by serializing the usage of page_frag_cache.
The Linux kernel CVE team has assigned CVE-2026-80862 to this issue.
Affected and fixed versions
===========================
Issue introduced in 6.12 with commit 4e893ca8117022de68ce1b61c0309e3d17bb8a25 and fixed in 6.12.108 with commit d19f98c79f1b7e09e4cdf5c20d626e571e487467
Issue introduced in 6.12 with commit 4e893ca8117022de68ce1b61c0309e3d17bb8a25 and fixed in 6.18.49 with commit 64561afb42d8390695bf810d9bbd087cbca00291
Issue introduced in 6.12 with commit 4e893ca8117022de68ce1b61c0309e3d17bb8a25 and fixed in 7.1.13 with commit 0a9750263ffacbbd2048a391fd4bd22e2146c57d
Issue introduced in 6.12 with commit 4e893ca8117022de68ce1b61c0309e3d17bb8a25 and fixed in 7.2.3 with commit 6e4cf281558709b92ec2ca3054fe2ffc69266ef9
Issue introduced in 6.12 with commit 4e893ca8117022de68ce1b61c0309e3d17bb8a25 and fixed in 7.3-rc1 with commit 36ac05f7cfd59d90c597071304b14e98090d5dd1
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-80862
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/nvme/host/tcp.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/d19f98c79f1b7e09e4cdf5c20d626e571e487467
https://git.kernel.org/stable/c/64561afb42d8390695bf810d9bbd087cbca00291
https://git.kernel.org/stable/c/0a9750263ffacbbd2048a391fd4bd22e2146c57d
https://git.kernel.org/stable/c/6e4cf281558709b92ec2ca3054fe2ffc69266ef9
https://git.kernel.org/stable/c/36ac05f7cfd59d90c597071304b14e98090d5dd1
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-04 15:59 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 15:53 CVE-2026-80862: nvme-tcp: fix usage of page_frag_cache Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.