All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-80790: nvmet-fc: fix invalid free in LS IOD error path
@ 2026-09-04 15:11 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-04 15:11 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

nvmet-fc: fix invalid free in LS IOD error path

nvmet_fc_alloc_ls_iodlist() advances iod while initializing the LS IOD
array. If an rqstbuf allocation or response buffer DMA mapping fails,
the unwind loop decrements iod past the start of the array. The final
kfree(iod) therefore frees an address before the allocated object.

This can be reproduced with nvme-fcloop and failslab by setting
fail-nth to 6 before creating a target port. KASAN reports:

  BUG: KASAN: invalid-free in nvmet_fc_register_targetport
  Free of addr ffff88816cf8ff48 by task nvmet_fail_nth/9552

Free the original allocation base stored in tgtport->iod instead. With
this fix applied, the same sysfs write with fail-nth=6 returns -ENOMEM
without any KASAN report.

The Linux kernel CVE team has assigned CVE-2026-80790 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 4.10 with commit c53432030d86429dc9fe5adc3d68cb9d1343b0b2 and fixed in 5.10.267 with commit b189c6e408896ccc23d2e76d7738847cdebf1532
	Issue introduced in 4.10 with commit c53432030d86429dc9fe5adc3d68cb9d1343b0b2 and fixed in 5.15.218 with commit 449e9c4f8db84ad9d9bb288029b230bcf590faa2
	Issue introduced in 4.10 with commit c53432030d86429dc9fe5adc3d68cb9d1343b0b2 and fixed in 6.1.185 with commit 1a8f007faefe8c226ec65896589f8d59b0a8d5a5
	Issue introduced in 4.10 with commit c53432030d86429dc9fe5adc3d68cb9d1343b0b2 and fixed in 6.6.154 with commit d094582cce9c08516d714e7436a8f3b9211dda90
	Issue introduced in 4.10 with commit c53432030d86429dc9fe5adc3d68cb9d1343b0b2 and fixed in 6.12.106 with commit 371fb1bf902adaa59be32bd7e904a5317e604fd0
	Issue introduced in 4.10 with commit c53432030d86429dc9fe5adc3d68cb9d1343b0b2 and fixed in 6.18.47 with commit 8bce9cd08aae4283badf8ddc11fbb6f57b75a81e
	Issue introduced in 4.10 with commit c53432030d86429dc9fe5adc3d68cb9d1343b0b2 and fixed in 7.1.11 with commit bb9489f0dce58da730d3479588d6710d7a2c1b45
	Issue introduced in 4.10 with commit c53432030d86429dc9fe5adc3d68cb9d1343b0b2 and fixed in 7.2.1 with commit 94334ea92f4d7535f66f86e33681efa94827eddc
	Issue introduced in 4.10 with commit c53432030d86429dc9fe5adc3d68cb9d1343b0b2 and fixed in 7.3-rc1 with commit ba98d6796d12258e837ece065d2ecb59d76ce4ff

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-80790
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/nvme/target/fc.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/b189c6e408896ccc23d2e76d7738847cdebf1532
	https://git.kernel.org/stable/c/449e9c4f8db84ad9d9bb288029b230bcf590faa2
	https://git.kernel.org/stable/c/1a8f007faefe8c226ec65896589f8d59b0a8d5a5
	https://git.kernel.org/stable/c/d094582cce9c08516d714e7436a8f3b9211dda90
	https://git.kernel.org/stable/c/371fb1bf902adaa59be32bd7e904a5317e604fd0
	https://git.kernel.org/stable/c/8bce9cd08aae4283badf8ddc11fbb6f57b75a81e
	https://git.kernel.org/stable/c/bb9489f0dce58da730d3479588d6710d7a2c1b45
	https://git.kernel.org/stable/c/94334ea92f4d7535f66f86e33681efa94827eddc
	https://git.kernel.org/stable/c/ba98d6796d12258e837ece065d2ecb59d76ce4ff

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-04 15:16 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 15:11 CVE-2026-80790: nvmet-fc: fix invalid free in LS IOD error path Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.