Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
738 articles · 106207 vulns · 36/50 feeds (7d)
← Back to list
9.8
CVE-2026-23112

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU lengt

Description

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU length or offset exceeds sg_cnt and then use bogus sg->length/offset values, leading to _copy_to_iter() GPF/KASAN. Guard sg_idx, remaining entries, and sg->length/offset before building the bvec.

Affected Products

VendorProductVersions
linuxlinux_kernel< 5.10.250, < 5.15.200, < 6.1.163, < 6.6.124, < 6.12.70, < 6.18.10

References

  • https://git.kernel.org/stable/c/043b4307a99f902697349128fde93b2ddde4686c(Patch)
  • https://git.kernel.org/stable/c/1385be357e8acd09b36e026567f3a9d5c61139de(Patch)
  • https://git.kernel.org/stable/c/19672ae68d52ff75347ebe2420dde1b07adca09f(Patch)
  • https://git.kernel.org/stable/c/42afe8ed8ad2de9c19457156244ef3e1eca94b5d(Patch)
  • https://git.kernel.org/stable/c/52a0a98549344ca20ad81a4176d68d28e3c05a5c(Patch)
  • https://git.kernel.org/stable/c/ab200d71553bdcf4de554a5985b05b2dd606bc57(Patch)
  • https://git.kernel.org/stable/c/dca1a6ba0da9f472ef040525fab10fd9956db59f(Patch)

Related News (2 articles)

Tier B
CERT-FR2d ago
Bulletin d'actualité CERTFR-2026-ACT-012 (23 mars 2026)
→ No new info (linked only)
Tier B
CERT-FR5d ago
Multiples vulnérabilités dans le noyau Linux de SUSE (20 mars 2026)
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-787
Published2/13/2026
Last enriched4h ago
Trending Score17
Source articles2
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%