PT-2026-93609 · Linux · Linux Kernel
CVE-2026-89968
·
Published
2026-09-16
·
Updated
2026-09-29
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the nvmet-tcp module where the
nvmet tcp handle h2c data pdu() function accepts an H2CData PDU without verifying if the target solicited the data by sending an R2T. A remote host can exploit this by submitting a write command and sending an H2CData PDU before the target transmits the R2T. This causes the command to complete early and potentially a second time if a synchronous failure occurs, such as a length mismatch detected by nvmet check transfer len(). Consequently, the same command is added to the queue->resp list twice, creating a self-referential node. When nvmet tcp process resp list() processes this node, it can lead to a kernel BUG if CONFIG DEBUG LIST is enabled, or a soft-lockup of the nvmet tcp workqueue if it is not. This can be triggered remotely without authentication on an allow any host subsystem.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel