All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-80791: nvmet-auth: zero the AUTH_RECEIVE response buffer
@ 2026-09-04 15:11 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-04 15:11 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

nvmet-auth: zero the AUTH_RECEIVE response buffer

nvmet_execute_auth_receive() allocates the response buffer with kmalloc()
sized by the host-supplied AUTH_RECEIVE allocation length, but the
DH-HMAC-CHAP builders write only a fixed-size message into it. The full
allocation length is then copied to the wire by nvmet_copy_to_sgl(), so a
remote initiator receives the bytes past the built message -- up to nearly
a page of uninitialized slab -- during the pre-authentication handshake.

Allocate the buffer with kzalloc() so the unwritten tail is zeroed before
it is sent; conforming responses are unaffected.

The Linux kernel CVE team has assigned CVE-2026-80791 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.0 with commit db1312dd95488b5e6ff362ff66fcf953a46b1821 and fixed in 6.1.185 with commit 447b668faa14710f611e714031e3739ac3ec3a4f
	Issue introduced in 6.0 with commit db1312dd95488b5e6ff362ff66fcf953a46b1821 and fixed in 6.6.154 with commit 8f6363c8d54dde95982f0ab45e77cf57ec0efd62
	Issue introduced in 6.0 with commit db1312dd95488b5e6ff362ff66fcf953a46b1821 and fixed in 6.12.106 with commit dfcf013f77709ebdb282767edc2795a37cab5b57
	Issue introduced in 6.0 with commit db1312dd95488b5e6ff362ff66fcf953a46b1821 and fixed in 6.18.47 with commit b26189d28442183a8b5edb754f4a6918f77ca84e
	Issue introduced in 6.0 with commit db1312dd95488b5e6ff362ff66fcf953a46b1821 and fixed in 7.1.11 with commit 2dcc9226203da7275a9c29d20007da278d73d5e9
	Issue introduced in 6.0 with commit db1312dd95488b5e6ff362ff66fcf953a46b1821 and fixed in 7.2.1 with commit 1d6837d98bf966a041af65de5f78de7409ff83bc
	Issue introduced in 6.0 with commit db1312dd95488b5e6ff362ff66fcf953a46b1821 and fixed in 7.3-rc1 with commit 3ddcfb013322aa37eaa7a0d344b73079c38dfa21

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-80791
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/nvme/target/fabrics-cmd-auth.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/447b668faa14710f611e714031e3739ac3ec3a4f
	https://git.kernel.org/stable/c/8f6363c8d54dde95982f0ab45e77cf57ec0efd62
	https://git.kernel.org/stable/c/dfcf013f77709ebdb282767edc2795a37cab5b57
	https://git.kernel.org/stable/c/b26189d28442183a8b5edb754f4a6918f77ca84e
	https://git.kernel.org/stable/c/2dcc9226203da7275a9c29d20007da278d73d5e9
	https://git.kernel.org/stable/c/1d6837d98bf966a041af65de5f78de7409ff83bc
	https://git.kernel.org/stable/c/3ddcfb013322aa37eaa7a0d344b73079c38dfa21

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-04 15:20 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 15:11 CVE-2026-80791: nvmet-auth: zero the AUTH_RECEIVE response buffer Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.