CVE-2026-80791

Unknown

Last modified

CVE-2026-80791 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: zero the AUTH_RECEIVE response buffer nvmet_execute_auth_receive() allocates the response buffer with kmalloc() sized by the host-supplied AUTH_RECEIVE allocation length, but the DH-HMAC-CHAP builders write only a fixed-size message into it. The full allocation length is then copied to the wire by nvmet_copy_to_sgl(), so a remote initiator receives the bytes past the built message -- up to nearly a page of uninitialized slab -- during the pre-authentication handshake. Allocate the buffer with kzalloc() so the unwritten tail is zeroed before it is sent; conforming responses are unaffected..

Description

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: zero the AUTH_RECEIVE response buffer nvmet_execute_auth_receive() allocates the response buffer with kmalloc() sized by the host-supplied AUTH_RECEIVE allocation length, but the DH-HMAC-CHAP builders write only a fixed-size message into it. The full allocation length is then copied to the wire by nvmet_copy_to_sgl(), so a remote initiator receives the bytes past the built message -- up to nearly a page of uninitialized slab -- during the pre-authentication handshake. Allocate the buffer with kzalloc() so the unwritten tail is zeroed before it is sent; conforming responses are unaffected.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= db1312dd95488b5e6ff362ff66fcf953a46b1821, < 447b668faa14710f611e714031e3739ac3ec3a4f; >= db1312dd95488b5e6ff362ff66fcf953a46b1821, < 8f6363c8d54dde95982f0ab45e77cf57ec0efd62; >= db1312dd95488b5e6ff362ff66fcf953a46b1821, < dfcf013f77709ebdb282767edc2795a37cab5b57; >= db1312dd95488b5e6ff362ff66fcf953a46b1821, < b26189d28442183a8b5edb754f4a6918f77ca84e; >= db1312dd95488b5e6ff362ff66fcf953a46b1821, < 2dcc9226203da7275a9c29d20007da278d73d5e9; >= db1312dd95488b5e6ff362ff66fcf953a46b1821, < 1d6837d98bf966a041af65de5f78de7409ff83bc; >= db1312dd95488b5e6ff362ff66fcf953a46b1821, < 3ddcfb013322aa37eaa7a0d344b73079c38dfa21
LinuxLinux6.0

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-80791?
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: zero the AUTH_RECEIVE response buffer nvmet_execute_auth_receive() allocates the response buffer with kmalloc() sized by the host-supplied AUTH_RECEIVE allocation length, but the DH-HMAC-CHAP builders write only a fixed-size message into it. The full allocation length is then copied to the wire by nvmet_copy_to_sgl(), so a remote initiator receives the bytes past the built message -- up to nearly a page of uninitialized slab -- during the pre-authentication handshake. Allocate the buffer with kzalloc() so the unwritten tail is zeroed before it is sent; conforming responses are unaffected.
How severe is CVE-2026-80791?
Severity scoring for CVE-2026-80791 is pending analysis.
How do I fix CVE-2026-80791?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-80791?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST