PT-2026-51883 · Linux+2 · Linux Kernel+2
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw in the
nvmet-tcp component occurs because the nvmet tcp build pdu iovec() function does not propagate errors to its callers when detecting out-of-bounds PDU (Protocol Data Unit) lengths or offsets. Because the function returns void, callers like nvmet tcp handle h2c data pdu() remain unaware of fatal errors, leaving the cmd->recv msg.msg iter uninitialized. This can result in the socket receiving loop attempting to read incoming network data into the uninitialized iterator, potentially leading to memory corruption, denial of service, or arbitrary code execution.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Initialization
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu