« Volver al listado

CVE-2026-89975

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

nvme-fabrics: fix DHCHAP secret leak on parse failure

nvmf_parse_options() duplicates dhchap_secret and dhchap_ctrl_secret with match_strdup() before validating the DHHC-1: representation.

If validation fails, the parser returns -EINVAL before the temporary string in p is assigned to opts->dhchap_secret or opts->dhchap_ctrl_secret. nvmf_create_ctrl() subsequently frees opts, but nvmf_free_options() cannot release the unassigned temporary string. Each rejected option therefore leaks one allocation.

This is easy to miss because valid secrets transfer ownership to opts and are freed normally, while the malformed-secret path still returns the expected -EINVAL to userspace.

Leer descripción completaMostrar menos

With CONFIG_NVME_HOST_AUTH enabled, the leak is reachable before the required-option checks and transport lookup. No NVMe-oF target or working transport connection is required; for example, repeatedly writing

or

to /dev/nvme-fabrics deterministically takes the leaking parse path.

Free the temporary string before leaving both validation error paths. Use kfree_sensitive() because the copied option may contain secret material even when its representation is rejected, matching the sensitive cleanup used for stored DHCHAP secrets.

Detalles técnicos trazas, registros y código del informe original
	dhchap_secret=BAD

	dhchap_ctrl_secret=BAD

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89975",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f50fff73d620cd6e8f48bc58d4f1c944615a3fea",
              "lessThan": "702c1ae0d31b44828ec3c87079def490c1ee1fb3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f50fff73d620cd6e8f48bc58d4f1c944615a3fea",
              "lessThan": "15d7a35a489287109b5a7c157d53d9b8214f0318",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f50fff73d620cd6e8f48bc58d4f1c944615a3fea",
              "lessThan": "d21da6cc91ba1c4f1ae5ba007f3cb89e1c0c7549",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f50fff73d620cd6e8f48bc58d4f1c944615a3fea",
              "lessThan": "afdee49a1b88ed9bb44e2b30e855297c169bcc53",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/nvme/host/fabrics.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/nvme/host/fabrics.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:08.337",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/15d7a35a489287109b5a7c157d53d9b8214f0318",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/702c1ae0d31b44828ec3c87079def490c1ee1fb3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/afdee49a1b88ed9bb44e2b30e855297c169bcc53",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d21da6cc91ba1c4f1ae5ba007f3cb89e1c0c7549",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-fabrics: fix DHCHAP secret leak on parse failure\n\nnvmf_parse_options() duplicates dhchap_secret and dhchap_ctrl_secret\nwith match_strdup() before validating the DHHC-1: representation.\n\nIf validation fails, the parser returns -EINVAL before the temporary\nstring in p is assigned to opts->dhchap_secret or\nopts->dhchap_ctrl_secret. nvmf_create_ctrl() subsequently frees opts,\nbut nvmf_free_options() cannot release the unassigned temporary string.\nEach rejected option therefore leaks one allocation.\n\nThis is easy to miss because valid secrets transfer ownership to opts\nand are freed normally, while the malformed-secret path still returns\nthe expected -EINVAL to userspace.\n\nWith CONFIG_NVME_HOST_AUTH enabled, the leak is reachable before the\nrequired-option checks and transport lookup. No NVMe-oF target or\nworking transport connection is required; for example, repeatedly\nwriting\n\n\tdhchap_secret=BAD\n\nor\n\n\tdhchap_ctrl_secret=BAD\n\nto /dev/nvme-fabrics deterministically takes the leaking parse path.\n\nFree the temporary string before leaving both validation error paths.\nUse kfree_sensitive() because the copied option may contain secret\nmaterial even when its representation is rejected, matching the\nsensitive cleanup used for stored DHCHAP secrets."
    }
  ],
  "lastModified": "2026-09-16T11:17:08.337",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}