CVE-2026-89973
CVE CVE-2026-89973EUVD EUVD-2026-80573Published 2026-09-16T10:32:52.000ZLast changed 2026-09-16T14:40:55.000ZCVSS 8.2
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: check the data direction of a C2HData PDU nvme_tcp_handle_c2h_data() finds the request by command id and checks that it has a payload, but it does not check that the command asked for data to be read. A controller that answers a write command with C2HData therefore reaches nvme_tcp_recv_data(), where _copy_to_iter() hits WARN_ON_ONCE(i->data_source) and returns 0. The receive path turns that into -EFAULT and resets the controller. No data is copied, so this is not memory corruption. What a controller gets is a kernel warning it can raise at will, which is fatal on a host booted with panic_on_warn. The send path already knows the direction - it consults rq_data_dir() when it builds a command - and nvme_tcp_handle_r2t() checks the length and the offset of the request it names. The C2HData path does not check the direction at all. Reject a C2HData PDU whose command is not a read. Rejecting it fails the command and resets the controller, as the neighbouring check in this function does; what goes away is the warning. [ 6.885580] ------------[ cut here ]------------ [ 6.886457] WARNING: lib/iov_iter.c:193 at _copy_to_iter+0x289/0x1330, CPU#0: kworker/0:1H/71 [ 6.888137] CPU: 0 UID: 0 PID: 71 Comm: kworker/0:1H Not tainted 7.2.0-rc5-NVMETCP-gf5098b6bae76 #1 PREEMPT(lazy) [ 6.891165] Workqueue: nvme_tcp_wq nvme_tcp_io_work [ 6.891875] RIP: 0010:_copy_to_iter+0x289/0x1330 [ 6.903739] Call Trace: [ 6.904085] <TASK> [ 6.909254] __skb_datagram_iter+0x433/0x820 [ 6.911026] skb_copy_datagram_iter+0x37/0x120 [ 6.911622] nvme_tcp_recv_skb+0xa07/0x4320 [ 6.913378] __tcp_read_sock+0x1ab/0x810 [ 6.915788] nvme_tcp_try_recv+0x152/0x1e0 [ 6.918222] nvme_tcp_io_work+0x1e4/0x6c0 [ 6.926906] </TASK> [ 6.927226] ---[ end trace 0000000000000000 ]--- [ 6.927878] nvme nvme0: queue 1 failed to copy request 0x71 data [ 6.928709] nvme nvme0: receive failed: -14
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.6.157; patch: 0; 3f2304f8c6d6ed97849057bd16fee99e434ca796 <0673a2affe45ca76b60de31a83c67b1e60f81bde; 3f2304f8c6d6ed97849057bd16fee99e434ca796 <80d56202fbdff8906be6954b2776e5c14a4026f2; patch: 7.2.5; 3f2304f8c6d6ed97849057bd16fee99e434ca796 <b4af7999a998787d5eb6facb5a333e04a4f1d2d9; 3f2304f8c6d6ed97849057bd16fee99e434ca796 <a0c389b8a495bda1eb719d2503853c924b7a8355; patch: 7.3-rc2; patch: 6.12.110; 3f2304f8c6d6ed97849057bd16fee99e434ca796 <980d990f3c0560d7dfbfbf14699651fdf02f26ee; patch: 6.18.51; patch: 6.1.188; 3f2304f8c6d6ed97849057bd16fee99e434ca796 <5b115d932f6e769ac80783fb18edd21b0aed256e; patch: 5.10.270; 3f2304f8c6d6ed97849057bd16fee99e434ca796 <df74950ba6008655d4a977d17df7faf4b6e52b74; 5.0; patch: 5.15.221; 3f2304f8c6d6ed97849057bd16fee99e434ca796 <f83af377c148f6ad94b41c0e8313f12adf45e1c1
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.