« Volver al listado

CVE-2026-80791

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

nvmet-auth: zero the AUTH_RECEIVE response buffer

nvmet_execute_auth_receive() allocates the response buffer with kmalloc() sized by the host-supplied AUTH_RECEIVE allocation length, but the DH-HMAC-CHAP builders write only a fixed-size message into it. The full allocation length is then copied to the wire by nvmet_copy_to_sgl(), so a remote initiator receives the bytes past the built message -- up to nearly a page of uninitialized slab -- during the pre-authentication handshake.

Allocate the buffer with kzalloc() so the unwritten tail is zeroed before it is sent; conforming responses are unaffected.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80791",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
              "lessThan": "447b668faa14710f611e714031e3739ac3ec3a4f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
              "lessThan": "8f6363c8d54dde95982f0ab45e77cf57ec0efd62",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
              "lessThan": "dfcf013f77709ebdb282767edc2795a37cab5b57",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
              "lessThan": "b26189d28442183a8b5edb754f4a6918f77ca84e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
              "lessThan": "2dcc9226203da7275a9c29d20007da278d73d5e9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
              "lessThan": "1d6837d98bf966a041af65de5f78de7409ff83bc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "db1312dd95488b5e6ff362ff66fcf953a46b1821",
              "lessThan": "3ddcfb013322aa37eaa7a0d344b73079c38dfa21",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/nvme/target/fabrics-cmd-auth.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.185",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.154",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.106",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.47",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/nvme/target/fabrics-cmd-auth.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:05.327",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1d6837d98bf966a041af65de5f78de7409ff83bc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2dcc9226203da7275a9c29d20007da278d73d5e9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3ddcfb013322aa37eaa7a0d344b73079c38dfa21",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/447b668faa14710f611e714031e3739ac3ec3a4f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8f6363c8d54dde95982f0ab45e77cf57ec0efd62",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b26189d28442183a8b5edb754f4a6918f77ca84e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dfcf013f77709ebdb282767edc2795a37cab5b57",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-auth: zero the AUTH_RECEIVE response buffer\n\nnvmet_execute_auth_receive() allocates the response buffer with kmalloc()\nsized by the host-supplied AUTH_RECEIVE allocation length, but the\nDH-HMAC-CHAP builders write only a fixed-size message into it. The full\nallocation length is then copied to the wire by nvmet_copy_to_sgl(), so a\nremote initiator receives the bytes past the built message -- up to nearly\na page of uninitialized slab -- during the pre-authentication handshake.\n\nAllocate the buffer with kzalloc() so the unwritten tail is zeroed before\nit is sent; conforming responses are unaffected."
    }
  ],
  "lastModified": "2026-09-04T16:18:05.327",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}