« Volver al listado

CVE-2026-80787

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()

nvmet_pci_epf_exec_iod_work() submits an I/O command with req->execute() and then waits for the command to complete and transfers the data back to the host. This wait is not needed for commands that do not transfer data from the device to the host. To decide whether that wait is needed, it reads iod->data_len and iod->dma_dir after calling req->execute().

However, once req->execute() is called, the command may complete asynchronously on another CPU.

Leer descripción completaMostrar menos

For commands that do not require a device-to-host data transfer, nvmet_pci_epf_queue_response() calls nvmet_pci_epf_complete_iod() directly, which can free the iod before it reads iod->data_len and iod->dma_dir, resulting in the KFENCE use-after- free:

kfence-#63: 0x00000000e3de0e71-0x00000000c938ad62, size=712, cache=kmalloc-1k

Fix this by referring to iod->data_len and iod->dma_dir before calling req->execute(). The remaining iod accesses such as iod->status are only reached on the device-to-host read path. In this case, nvmet_pci_epf_queue_response() signals iod->done instead of freeing the iod, so the iod stays valid.

Detalles técnicos trazas, registros y código del informe original
 BUG: KFENCE: use-after-free read in nvmet_pci_epf_exec_iod_work+0x288/0x798 [nvmet_pci_epf]

 Use-after-free read at 0x00000000fdfa6d03 (in kfence-#63):
  nvmet_pci_epf_exec_iod_work+0x288/0x798 [nvmet_pci_epf]
  process_one_work+0x15c/0x4f0
  worker_thread+0x18c/0x30c
  kthread+0x130/0x140
  ret_from_fork+0x10/0x20

 allocated by task 10 on cpu 0 at 73.995480s (0.005122s ago):
  mempool_kmalloc+0x1c/0x28
  mempool_alloc_noprof+0x40/0x9c
  nvmet_pci_epf_poll_sqs_work+0xd4/0x344 [nvmet_pci_epf]
  process_one_work+0x15c/0x4f0
  worker_thread+0x18c/0x30c
  kthread+0x130/0x140
  ret_from_fork+0x10/0x20

 freed by task 131 on cpu 3 at 73.995521s (0.008385s ago):
  mempool_kfree+0x10/0x20
  mempool_free+0x44/0x64
  nvmet_pci_epf_free_iod+0x88/0x98 [nvmet_pci_epf]
  nvmet_pci_epf_cq_work+0xfc/0x280 [nvmet_pci_epf]
  process_one_work+0x15c/0x4f0
  worker_thread+0x18c/0x30c
  kthread+0x130/0x140
  ret_from_fork+0x10/0x20

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80787",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186",
              "lessThan": "20be486d1c225402b067391e72ff5b0dd8ebff76",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186",
              "lessThan": "1ed1eeaef55cebf2d74b3ef104c20bdab719b165",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186",
              "lessThan": "cede8d2852570c79b9bbb9527255ae9ed3317b82",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186",
              "lessThan": "c9e9bb757971485b4e8414b1744507af186d72c9",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/nvme/target/pci-epf.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.47",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/nvme/target/pci-epf.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:04.710",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1ed1eeaef55cebf2d74b3ef104c20bdab719b165",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/20be486d1c225402b067391e72ff5b0dd8ebff76",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c9e9bb757971485b4e8414b1744507af186d72c9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cede8d2852570c79b9bbb9527255ae9ed3317b82",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()\n\nnvmet_pci_epf_exec_iod_work() submits an I/O command with req->execute()\nand then waits for the command to complete and transfers the data back\nto the host. This wait is not needed for commands that do not transfer\ndata from the device to the host. To decide whether that wait is needed,\nit reads iod->data_len and iod->dma_dir after calling req->execute().\n\nHowever, once req->execute() is called, the command may complete\nasynchronously on another CPU. For commands that do not require a\ndevice-to-host data transfer, nvmet_pci_epf_queue_response() calls\nnvmet_pci_epf_complete_iod() directly, which can free the iod before it\nreads iod->data_len and iod->dma_dir, resulting in the KFENCE use-after-\nfree:\n\n BUG: KFENCE: use-after-free read in nvmet_pci_epf_exec_iod_work+0x288/0x798 [nvmet_pci_epf]\n\n Use-after-free read at 0x00000000fdfa6d03 (in kfence-#63):\n  nvmet_pci_epf_exec_iod_work+0x288/0x798 [nvmet_pci_epf]\n  process_one_work+0x15c/0x4f0\n  worker_thread+0x18c/0x30c\n  kthread+0x130/0x140\n  ret_from_fork+0x10/0x20\n\n kfence-#63: 0x00000000e3de0e71-0x00000000c938ad62, size=712, cache=kmalloc-1k\n\n allocated by task 10 on cpu 0 at 73.995480s (0.005122s ago):\n  mempool_kmalloc+0x1c/0x28\n  mempool_alloc_noprof+0x40/0x9c\n  nvmet_pci_epf_poll_sqs_work+0xd4/0x344 [nvmet_pci_epf]\n  process_one_work+0x15c/0x4f0\n  worker_thread+0x18c/0x30c\n  kthread+0x130/0x140\n  ret_from_fork+0x10/0x20\n\n freed by task 131 on cpu 3 at 73.995521s (0.008385s ago):\n  mempool_kfree+0x10/0x20\n  mempool_free+0x44/0x64\n  nvmet_pci_epf_free_iod+0x88/0x98 [nvmet_pci_epf]\n  nvmet_pci_epf_cq_work+0xfc/0x280 [nvmet_pci_epf]\n  process_one_work+0x15c/0x4f0\n  worker_thread+0x18c/0x30c\n  kthread+0x130/0x140\n  ret_from_fork+0x10/0x20\n\nFix this by referring to iod->data_len and iod->dma_dir before calling\nreq->execute(). The remaining iod accesses such as iod->status are only\nreached on the device-to-host read path. In this case,\nnvmet_pci_epf_queue_response() signals iod->done instead of freeing the\niod, so the iod stays valid."
    }
  ],
  "lastModified": "2026-09-04T16:18:04.710",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}