CVE-2026-89480
Received Received - Intake

NVMe/TCP Insufficient Read Data Validation

Vulnerability report for CVE-2026-89480, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: reject a read that transferred too few bytes nvme_tcp_recv_data() completes a request once the current C2HData PDU has been consumed. Nothing compares the total bytes received against the length the command asked for: struct nvme_tcp_request has no receive-side counter, queue->data_remaining is per queue, and blk_mq_end_request() completes for blk_rq_bytes(rq) unconditionally with no residual concept anywhere above. A controller can therefore answer a 4096-byte read with 512 bytes and have it reported as a complete read; user space then gets 4096 bytes of which 3584 are whatever was already in the page. I reproduced that with a test target. Count the bytes received and refuse to complete a successful read whose count does not match, at the two NVME_TCP_F_DATA_SUCCESS paths and in nvme_tcp_process_nvme_cqe(). The success test shifts req->status right by one, because the driver keeps the wire value there and shifts it on completion, so the check must see what the completion path will see. Only REQ_OP_READ is checked, because there the length comes from the sectors the request covers; a passthrough command is built by its submitter, which picks both command and buffer, so the kernel has nothing to compare against.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves the NVMe over TCP (nvme-tcp) driver incorrectly handling read operations. When a read request is made, the driver completes it without verifying if the correct number of bytes were transferred. This allows a malicious controller to send fewer bytes than requested, leading to incomplete data reads where the remaining bytes contain stale memory contents.

Detection Guidance

This vulnerability affects the NVMe over TCP (nvme-tcp) driver in the Linux kernel. Detection requires checking kernel logs for NVMe TCP errors or mismatched read byte counts. Monitor for kernel messages indicating incomplete or truncated NVMe read operations. Use commands like 'dmesg | grep nvme' or 'journalctl -k | grep nvme' to inspect kernel logs for errors related to NVMe TCP data transfers.

Impact Analysis

This vulnerability could allow attackers to read sensitive or privileged memory contents from the system. If exploited, it may lead to information disclosure, privilege escalation, or other security breaches depending on the data exposed.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by enabling unauthorized data exposure. A malicious controller could send incomplete read responses, causing user space to receive uninitialized memory or residual data. This may lead to unintended data disclosure, violating confidentiality requirements in GDPR and HIPAA.

Mitigation Strategies

Immediately update the Linux kernel to a patched version that includes the fix for this vulnerability. Disable NVMe over TCP if not required. Monitor vendor advisories for kernel updates and apply them promptly. If using NVMe over TCP, restrict network access to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89480. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart