---
id: CVE-2026-90230
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()

  nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with
  the host-supplied transfer length…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()

  nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with
  the host-supplied transfer length…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= db1312dd95488b5e6ff362ff66fcf953a46b1821 <
    89ff11b72f38976f3b5aea23a5228ee05e277209
  - >-
    Linux >= db1312dd95488b5e6ff362ff66fcf953a46b1821 <
    aaac783950b17c57df9b6f7344747cacb1a407ed
  - >-
    Linux >= db1312dd95488b5e6ff362ff66fcf953a46b1821 <
    c38a8186326799957d293d370136c128cd113916
  - >-
    Linux >= db1312dd95488b5e6ff362ff66fcf953a46b1821 <
    7b81e4d2230e3d2d372c826180c4ef0efc244f31
  - >-
    Linux >= db1312dd95488b5e6ff362ff66fcf953a46b1821 <
    5bb96cc218835769ab74ec7f3ea2bf81fbffe955
  - Linux 6.0
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:47.987'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90230'
references:
  - url: 'https://git.kernel.org/stable/c/5bb96cc218835769ab74ec7f3ea2bf81fbffe955'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7b81e4d2230e3d2d372c826180c4ef0efc244f31'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/89ff11b72f38976f3b5aea23a5228ee05e277209'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/aaac783950b17c57df9b6f7344747cacb1a407ed'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c38a8186326799957d293d370136c128cd113916'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00457
epssPercentile: 0.38991
ingestedAt: '2026-09-17T16:21:47.852Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()

nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with
the host-supplied transfer length (tl) and hands it to
nvmet_auth_negotiate() without passing tl along. nvmet_auth_negotiate()
then reads the negotiate header and, for each of the halen hash
identifiers and dhlen DH group identifiers, indexes into the fixed
idlist[60] array (hashes at idlist[0..halen), groups at idlist[30..]).

Neither the transfer length nor halen/dhlen is validated. A malicious or
non-conformant host can report a tl smaller than the negotiate structure,
or a halen/dhlen larger than the array (both are u8, up to 255), making
the loops read past the end of the allocated buffer (heap out-of-bounds
read). The sibling nvmet_auth_reply() already validates tl against the
structure size; the negotiate path did not.

Pass tl into nvmet_auth_negotiate(), reject a tl that does not cover the
negotiate data plus one full protocol descriptor, and reject halen/dhlen
larger than NVME_AUTH_DHCHAP_MAX_DH_IDS.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
