OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-90230

CRITICAL · CVSS 9.1 EPSS 0.65%

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the nvmet subsystem, specifically in the handling of authentication negotiation, where insufficient validation of user-supplied parameters can lead to a heap out-of-bounds read. This flaw allows a malicious host to potentially exploit memory, which could lead to information disclosure or instability in the system. Organizations using affected Linux distributions should prioritize patching this vulnerability to safeguard against potential exploitation.

CVE
CVE-2026-90230
Severity
CRITICAL
CVSS
9.1
EPSS
0.65%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with the host-supplied transfer length (tl) and hands it to nvmet_auth_negotiate() without passing tl along. nvmet_auth_negotiate() then reads the negotiate header and, for each of the halen hash identifiers and dhlen DH group identifiers, indexes into the fixed idlist[60] array (hashes at idlist[0..halen), groups at idlist[30..]). Neither the transfer length nor halen/dhlen is validated. A malicious or non-conformant host can report a tl smaller than the negotiate structure, or a halen/dhlen larger than the array (both are u8, up to 255), making the loops read past the end of the allocated buffer (heap out-of-bounds read). The sibling nvmet_auth_reply() already validates tl against the structure size; the negotiate path did not. Pass tl into nvmet_auth_negotiate(), reject a tl that does not cover the negotiate data plus one full protocol descriptor, and reject halen/dhlen larger than NVME_AUTH_DHCHAP_MAX_DH_IDS.