---
cve: "CVE-2026-90230"
severity: "CRITICAL"
cvss: 9.1
epss: "0.5%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-09-17 17:17:18"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-21T04:44:02+02:00"
---

# CVE-2026-90230

> 9.1 CRITICAL

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()

nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with
the host-supplied transfer length (tl) and hands it to
nvmet_auth_negotiate() without passing tl along. nvmet_auth_negotiate()
then reads the negotiate header and, for each of the halen hash
identifiers and dhlen DH group identifiers, indexes into the fixed
idlist[60] array (hashes at idlist[0..halen), groups at idlist[30..]).

Neither the transfer length nor halen/dhlen is validated. A malicious or
non-conformant host can report a tl smaller than the negotiate structure,
or a halen/dhlen larger than the array (both are u8, up to 255), making
the loops read past the end of the allocated buffer (heap out-of-bounds
read). The sibling nvmet_auth_reply() already validates tl against the
structure size; the negotiate path did not.

Pass tl into nvmet_auth_negotiate(), reject a tl that does not cover the
negotiate data plus one full protocol descriptor, and reject halen/dhlen
larger than NVME_AUTH_DHCHAP_MAX_DH_IDS.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- Kernel ≥ 6.6.157
- Kernel ≥ 6.12.110
- Kernel ≥ 6.18.52
- Kernel ≥ 7.2.6

## Referenzen

- <https://git.kernel.org/stable/c/89ff11b72f38976f3b5aea23a5228ee05e277209>
- <https://git.kernel.org/stable/c/aaac783950b17c57df9b6f7344747cacb1a407ed>
- <https://git.kernel.org/stable/c/c38a8186326799957d293d370136c128cd113916>
- <https://git.kernel.org/stable/c/7b81e4d2230e3d2d372c826180c4ef0efc244f31>
- <https://git.kernel.org/stable/c/5bb96cc218835769ab74ec7f3ea2bf81fbffe955>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-90230) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
