From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B22E151355C for ; Fri, 4 Sep 2026 15:59:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788537565; cv=none; b=KEKMdgyGxjxztT+GqlKTjgDqwQ6kkdqJgtMy0rGYz5QiC9yPSLv7uhUpujX8B8odTjUK6Ho6k2Rf7HQAqwTDRLLKsLEWIU/XomrpWqoWrpLZKk4me3QQ1WDwSgVG/8VHbq0RdF6x/JswsjlMGGR6Rzs6E12yz9OvjoecMuxL4Mc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788537565; c=relaxed/simple; bh=F8fXFjvGJHIhRj4AOzJ1GwxznT1m5vW+olH//JQy/Kc=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=C1HTzWte4oydhm1zY0m1MgqNC+MDelUprmlSk+mZKorC7nrnfbVw3LbF3RehCIECXbyDEkhwCS+mjCvuwOENc+QRDzN4IWyS9alUdywxEEpkfmnRXR3jjmnAW1QX1l6JQB2TuTdcppLYgBq1622uaFNzFW/Qf5mh+y9QBmOOYRk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=LXvRDskn; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="LXvRDskn" Received: by smtp.kernel.org (Postfix) with ESMTPSA id A0B1B1F00ADB; Fri, 4 Sep 2026 15:59:20 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788537561; bh=AFP5FmQfM1SQ1bG1aDqlB0AKziow43bmUe3pcC6OLqs=; h=From:To:Cc:Subject:Date:Reply-To; b=LXvRDsknRlkl2k+z6dLGGWKeKCBXgwpvxyyEC5BCbThLlz6uEWTJ9ziN+KNPDLWXa i8SVdJV/LR3M4xOXqs2jazS4sat6zoJg31JgKB1v0vfIx2KFWdVLhaCGFKPVLbGb+k Kjyw3pmH9c7sZqaJ+k7nHgEY6qfuA+T3Hg3qOpng= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80862: nvme-tcp: fix usage of page_frag_cache Date: Fri, 4 Sep 2026 17:53:29 +0200 Message-ID: <2026090403-CVE-2026-80862-46f4@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3074; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=NjnuxgOvqip1QtaRyvCyfunOLIvgCh2X9XhgGUAUBeY=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmzXsbHv7h8zCem9+FE+3JPwbZzJisqrNu9StUUp4Zxi 31/dtW7I5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACbSp8wwv6Zr2sElzy6q8+85 L3O9O2zOY56QaQzzbEzfpfla7jq5SULCJDtC135nu9B+AA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix usage of page_frag_cache nvme uses page_frag_cache to preallocate PDU for each preallocated request of block device. Block devices are created in parallel threads, consequently page_frag_cache is used in not thread-safe manner. That leads to incorrect refcounting of backstore pages and premature free. That can be catched by !sendpage_ok inside network stack: WARNING: CPU: 7 PID: 467 at ../net/core/skbuff.c:6931 skb_splice_from_iter+0xfa/0x310. tcp_sendmsg_locked+0x782/0xce0 tcp_sendmsg+0x27/0x40 sock_sendmsg+0x8b/0xa0 nvme_tcp_try_send_cmd_pdu+0x149/0x2a0 Then random panic may occur. Fix that by serializing the usage of page_frag_cache. The Linux kernel CVE team has assigned CVE-2026-80862 to this issue. Affected and fixed versions =========================== Issue introduced in 6.12 with commit 4e893ca8117022de68ce1b61c0309e3d17bb8a25 and fixed in 6.12.108 with commit d19f98c79f1b7e09e4cdf5c20d626e571e487467 Issue introduced in 6.12 with commit 4e893ca8117022de68ce1b61c0309e3d17bb8a25 and fixed in 6.18.49 with commit 64561afb42d8390695bf810d9bbd087cbca00291 Issue introduced in 6.12 with commit 4e893ca8117022de68ce1b61c0309e3d17bb8a25 and fixed in 7.1.13 with commit 0a9750263ffacbbd2048a391fd4bd22e2146c57d Issue introduced in 6.12 with commit 4e893ca8117022de68ce1b61c0309e3d17bb8a25 and fixed in 7.2.3 with commit 6e4cf281558709b92ec2ca3054fe2ffc69266ef9 Issue introduced in 6.12 with commit 4e893ca8117022de68ce1b61c0309e3d17bb8a25 and fixed in 7.3-rc1 with commit 36ac05f7cfd59d90c597071304b14e98090d5dd1 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80862 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/nvme/host/tcp.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/d19f98c79f1b7e09e4cdf5c20d626e571e487467 https://git.kernel.org/stable/c/64561afb42d8390695bf810d9bbd087cbca00291 https://git.kernel.org/stable/c/0a9750263ffacbbd2048a391fd4bd22e2146c57d https://git.kernel.org/stable/c/6e4cf281558709b92ec2ca3054fe2ffc69266ef9 https://git.kernel.org/stable/c/36ac05f7cfd59d90c597071304b14e98090d5dd1