CVE-2026-97433
8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
nvme: validate FDP configuration descriptor sizes
Validate descriptor sizes while walking the FDP configurations log so dsze == 0 or a descriptor past the log end cannot cause unbounded iteration or reads past the buffer.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 30b5f20bb2ddab013035399e5c7e6577da49320a < 97efd7a41aac08b43ea2337c5913a2bc75484f9f | affected |
| Linux | Linux | 30b5f20bb2ddab013035399e5c7e6577da49320a < 0ef4daa6534a510d61ea67c8ad9bb5097b0dd5f8 | affected |
| Linux | Linux | 6.16 | affected |
| Linux | Linux | 0 < 6.16 | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/97efd7a41aac08b43ea2337c5913a2bc75484f9f
- https://git.kernel.org/stable/c/0ef4daa6534a510d61ea67c8ad9bb5097b0dd5f8
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.