CVE-2026-64319 Details
Description
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (hash length) and dhvlen (DH value length) fields without verifying they fit within the allocated buffer of tl bytes. A malicious NVMe-oF initiator can craft a DHCHAP_REPLY message with a small transfer length but large hl/dhvlen values, causing out-of-bounds heap reads when the target processes the DH public key (rval + 2*hl) or performs the host response memcmp. With DH authentication configured, the OOB pointer is passed directly to sg_init_one() and read by crypto_kpp_compute_shared_secret(), reaching up to 526 bytes past the buffer. This is exploitable pre-authentication. Add bounds validation ensuring sizeof(*data) + 2*hl + dhvlen <= tl before any access to the variable-length fields. Discovered by Atuin - Automated Vulnerability Discovery Engine.
A vulnerability in the Linux kernel's NVMe over Fabrics (NVMe-oF) implementation allows for out-of-bounds heap reads during the authentication process. The issue arises in the 'nvmet_auth_reply' function, which processes variable-length data arrays using attacker-controlled fields that specify hash and DH value lengths. This lack of proper validation can lead to memory reads beyond the allocated buffer, potentially exposing sensitive information or causing other unintended effects. The vulnerability is present in the NVMe-oF authentication reply handling, specifically when DH authentication is enabled.
The vulnerability has been addressed by adding proper bounds validation to ensure that the variable-length fields do not exceed the allocated buffer size. Users should upgrade to the latest patched version of the Linux kernel.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/3a413ece2504c70aa34a20be4dafec04e8c741f9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6d7649c1231dac14d906985d2936967e23041c26 | kernel.org | Patch |
| https://git.kernel.org/stable/c/80cd28b56ab62d3e7ed0a7bf05282e6d3ee5b2a0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/999f6205ede984a786f35f727b01f971b98e215d | kernel.org | Patch |
| https://git.kernel.org/stable/c/caa71b3a43ea5c13fe7141cb019ebcb03b8ac857 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.0, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 27, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |