CVE-2026-80813
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
When a host issues an Identify command with CNS 07h (Active Namespace ID List for a specific I/O Command Set), nvmet_execute_identify_nslist() is called with match_css set. The command-set filter dereferences req->ns, but this handler never calls nvmet_req_find_ns(), so req->ns is always NULL (nvmet_req_init() resets it to NULL). As soon as an enabled namespace with an NSID greater than the requested value exists, req->ns->csi dereferences a NULL pointer and oopses.
Besides the crash, the comparison is logically wrong: to filter the list by command set it must test the command set of the namespace being iterated, not a single fixed value. Use the loop variable ns->csi.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 61c9967cd63448292a64f9ee9aeb6e2053e3a624 < 61dc1a37e04d4003a19095f54883358330034a39 | affected |
| Linux | Linux | 61c9967cd63448292a64f9ee9aeb6e2053e3a624 < 2bc1e33ff6a558c8ceef7c0077f3ef70a15fcba2 | affected |
| Linux | Linux | 61c9967cd63448292a64f9ee9aeb6e2053e3a624 < 123d664ac98d6f3464462ad4a530474b91ba9890 | affected |
| Linux | Linux | 61c9967cd63448292a64f9ee9aeb6e2053e3a624 < 79aba4c9403419d822972d2851f2a96a2c0531cf | affected |
| Linux | Linux | 6.13 | affected |
| Linux | Linux | 0 < 6.13 | unaffected |
| Linux | Linux | 6.18.47 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.11 <= 7.1.* | unaffected |
| Linux | Linux | 7.2.1 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/61dc1a37e04d4003a19095f54883358330034a39
- https://git.kernel.org/stable/c/2bc1e33ff6a558c8ceef7c0077f3ef70a15fcba2
- https://git.kernel.org/stable/c/123d664ac98d6f3464462ad4a530474b91ba9890
- https://git.kernel.org/stable/c/79aba4c9403419d822972d2851f2a96a2c0531cf
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.