Bug 2532184 (CVE-2026-89481)
| Summary: | CVE-2026-89481 kernel: nvme-tcp: fix host memory disclosure on R2T for a read command | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | akhatavk, aos-team-art-private, asdas, dpaolell, jdelft, jupierce, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, rhel-process-autobot, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's NVMe (Non-Volatile Memory Express) over TCP (nvme-tcp) component. A malicious NVMe controller can exploit this vulnerability by sending a Ready to Transfer (R2T) command for a read request. The host system, failing to properly validate the request direction, will then send the contents of its read destination buffer to the controller. This can lead to the disclosure of stale kernel memory data, potentially revealing sensitive information.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-11 21:11:12 UTC
Upstream advisory: https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89481.mbox This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:71602 https://access.redhat.com/errata/RHSA-2026:71602 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:75746 https://access.redhat.com/errata/RHSA-2026:75746 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:75747 https://access.redhat.com/errata/RHSA-2026:75747 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:76739 https://access.redhat.com/errata/RHSA-2026:76739 |