From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 002F14EE878 for ; Fri, 4 Sep 2026 15:16:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788534977; cv=none; b=AgClv966jLfqZoXyj1UltNtYXmRF4rlR34mWFYsrK98+JoC2DqfWciFZhI4ECL8aK2+mYhdFT9hRh/Zr+Xrd2/ME+z7Z6FuV0/q2lKpfl24ByC6c7aBQYUnPDWDnjShz8a9DpROIRQlJrAIHODuVJntnwL5XLG5CDSNqwGqeotE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788534977; c=relaxed/simple; bh=QTaHEyE4n54AWnStgMxQGDBBs3MJ7YbQFAgBFHUSaPs=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=e3v4t67w+m+HKccngATzYNOS0xRAOZpEXLvVD6NUoGMYO9+SuwZMg/tTZtwP+sfsezkAB78ObK4fronUopyC78m6TAFi7GDOVYf52FF+VdYg8n5vthm5dPePDk+Ca5qd8rregscuku/OrcZo+z7DoY+BSiM1dtGnFzA2Sqs8NOg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=u/jtwKwW; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="u/jtwKwW" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E45D01F00A3E; Fri, 4 Sep 2026 15:16:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788534971; bh=5bcMN6z561QKhKsSD01+xZLElZPZ6LtxlKFuKAxcPJw=; h=From:To:Cc:Subject:Date:Reply-To; b=u/jtwKwW7bHGgsMHsVPQnWvW/90jXlyufsCy0N3If1LOGFUs5KtcSH0AMArjnbIzF dCZ+sulu1+zsHaCCy2vgBxKkMkAxlA7QglfZor21a1v21Xbr1HjYznxT/cOdqu9+iY P5ahCKBsdYWlyyRFkB1P3PkwJaCIXZOA/Wnm2Yhw= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80787: nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() Date: Fri, 4 Sep 2026 17:11:26 +0200 Message-ID: <2026090405-CVE-2026-80787-d0b7@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4301; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=HNtA4+AvYWoZ3aToUk16XqQz8tI4JINi94UbUmJ4GV4=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmz7neafN7q/OTRLI+LTkZuGXqFmnZSk6cGmjy4EVv+6 FZe4eTYjlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZjI7/cM8zN+CB/N/TDj1Jb2 dE+ptz2bPQ7ZMzMs2Gn998LxLSFVE412ruhTCX0YxpUyBwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() nvmet_pci_epf_exec_iod_work() submits an I/O command with req->execute() and then waits for the command to complete and transfers the data back to the host. This wait is not needed for commands that do not transfer data from the device to the host. To decide whether that wait is needed, it reads iod->data_len and iod->dma_dir after calling req->execute(). However, once req->execute() is called, the command may complete asynchronously on another CPU. For commands that do not require a device-to-host data transfer, nvmet_pci_epf_queue_response() calls nvmet_pci_epf_complete_iod() directly, which can free the iod before it reads iod->data_len and iod->dma_dir, resulting in the KFENCE use-after- free: BUG: KFENCE: use-after-free read in nvmet_pci_epf_exec_iod_work+0x288/0x798 [nvmet_pci_epf] Use-after-free read at 0x00000000fdfa6d03 (in kfence-#63): nvmet_pci_epf_exec_iod_work+0x288/0x798 [nvmet_pci_epf] process_one_work+0x15c/0x4f0 worker_thread+0x18c/0x30c kthread+0x130/0x140 ret_from_fork+0x10/0x20 kfence-#63: 0x00000000e3de0e71-0x00000000c938ad62, size=712, cache=kmalloc-1k allocated by task 10 on cpu 0 at 73.995480s (0.005122s ago): mempool_kmalloc+0x1c/0x28 mempool_alloc_noprof+0x40/0x9c nvmet_pci_epf_poll_sqs_work+0xd4/0x344 [nvmet_pci_epf] process_one_work+0x15c/0x4f0 worker_thread+0x18c/0x30c kthread+0x130/0x140 ret_from_fork+0x10/0x20 freed by task 131 on cpu 3 at 73.995521s (0.008385s ago): mempool_kfree+0x10/0x20 mempool_free+0x44/0x64 nvmet_pci_epf_free_iod+0x88/0x98 [nvmet_pci_epf] nvmet_pci_epf_cq_work+0xfc/0x280 [nvmet_pci_epf] process_one_work+0x15c/0x4f0 worker_thread+0x18c/0x30c kthread+0x130/0x140 ret_from_fork+0x10/0x20 Fix this by referring to iod->data_len and iod->dma_dir before calling req->execute(). The remaining iod accesses such as iod->status are only reached on the device-to-host read path. In this case, nvmet_pci_epf_queue_response() signals iod->done instead of freeing the iod, so the iod stays valid. The Linux kernel CVE team has assigned CVE-2026-80787 to this issue. Affected and fixed versions =========================== Issue introduced in 6.14 with commit 0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186 and fixed in 6.18.47 with commit 20be486d1c225402b067391e72ff5b0dd8ebff76 Issue introduced in 6.14 with commit 0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186 and fixed in 7.1.11 with commit 1ed1eeaef55cebf2d74b3ef104c20bdab719b165 Issue introduced in 6.14 with commit 0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186 and fixed in 7.2.1 with commit cede8d2852570c79b9bbb9527255ae9ed3317b82 Issue introduced in 6.14 with commit 0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186 and fixed in 7.3-rc1 with commit c9e9bb757971485b4e8414b1744507af186d72c9 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80787 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/nvme/target/pci-epf.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/20be486d1c225402b067391e72ff5b0dd8ebff76 https://git.kernel.org/stable/c/1ed1eeaef55cebf2d74b3ef104c20bdab719b165 https://git.kernel.org/stable/c/cede8d2852570c79b9bbb9527255ae9ed3317b82 https://git.kernel.org/stable/c/c9e9bb757971485b4e8414b1744507af186d72c9