« Volver al listado

CVE-2026-80813

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()

When a host issues an Identify command with CNS 07h (Active Namespace ID List for a specific I/O Command Set), nvmet_execute_identify_nslist() is called with match_css set. The command-set filter dereferences req->ns, but this handler never calls nvmet_req_find_ns(), so req->ns is always NULL (nvmet_req_init() resets it to NULL). As soon as an enabled namespace with an NSID greater than the requested value exists, req->ns->csi dereferences a NULL pointer and oopses.

Leer descripción completaMostrar menos

Besides the crash, the comparison is logically wrong: to filter the list by command set it must test the command set of the namespace being iterated, not a single fixed value. Use the loop variable ns->csi.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80813",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "61c9967cd63448292a64f9ee9aeb6e2053e3a624",
              "lessThan": "61dc1a37e04d4003a19095f54883358330034a39",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "61c9967cd63448292a64f9ee9aeb6e2053e3a624",
              "lessThan": "2bc1e33ff6a558c8ceef7c0077f3ef70a15fcba2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "61c9967cd63448292a64f9ee9aeb6e2053e3a624",
              "lessThan": "123d664ac98d6f3464462ad4a530474b91ba9890",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "61c9967cd63448292a64f9ee9aeb6e2053e3a624",
              "lessThan": "79aba4c9403419d822972d2851f2a96a2c0531cf",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/nvme/target/admin-cmd.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.47",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/nvme/target/admin-cmd.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:08.793",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/123d664ac98d6f3464462ad4a530474b91ba9890",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2bc1e33ff6a558c8ceef7c0077f3ef70a15fcba2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/61dc1a37e04d4003a19095f54883358330034a39",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/79aba4c9403419d822972d2851f2a96a2c0531cf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()\n\nWhen a host issues an Identify command with CNS 07h (Active Namespace ID\nList for a specific I/O Command Set), nvmet_execute_identify_nslist() is\ncalled with match_css set. The command-set filter dereferences req->ns,\nbut this handler never calls nvmet_req_find_ns(), so req->ns is always\nNULL (nvmet_req_init() resets it to NULL). As soon as an enabled\nnamespace with an NSID greater than the requested value exists,\nreq->ns->csi dereferences a NULL pointer and oopses.\n\nBesides the crash, the comparison is logically wrong: to filter the list\nby command set it must test the command set of the namespace being\niterated, not a single fixed value. Use the loop variable ns->csi."
    }
  ],
  "lastModified": "2026-09-04T16:18:08.793",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}