CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-64319

Critical · CVSS 9.1
CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable

Description

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (hash length) and dhvlen (DH value length) fields without verifying they fit within the allocated buffer of tl bytes. A malicious NVMe-oF initiator can craft a DHCHAP_REPLY message with a small transfer length but large hl/dhvlen values, causing out-of-bounds heap reads when the target processes the DH public key (rval + 2*hl) or performs the host response memcmp. With DH authentication configured, the OOB pointer is passed directly to sg_init_one() and read by crypto_kpp_compute_shared_secret(), reaching up to 526 bytes past the buffer. This is exploitable pre-authentication. Add bounds validation ensuring sizeof(*data) + 2*hl + dhvlen <= tl before any access to the variable-length fields. Discovered by Atuin - Automated Vulnerability Discovery Engine.

Affected packages

Linux Kernel 6.0.0 → 6.6.145
Linux Kernel 6.13.0 → 6.18.39
Linux Kernel 6.19.0 → 7.1.4
Linux Kernel 6.7.0 → 6.12.96

References

Status: profiled · ingested 2026-07-27T06:00:00.000Z