PT-2026-4660 · Linux+3 · Linux Kernel+3

Published

2025-12-13

·

Updated

2026-06-16

·

CVE-2026-22998

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the nvme-tcp subsystem, specifically in the nvmet tcp build pdu iovec() function. This function can dereference null pointers without proper checks when processing H2C DATA Protocol Data Units (PDUs). This can occur before a CONNECT command or NVMe write command is sent, or during READ commands where cmd->req.sg is allocated but cmd->iov is null. The issue stems from a lack of validation of cmd->req.sg and cmd->iov before they are used, potentially leading to a kernel panic. The fix involves adding validation checks for both pointers before calling nvmet tcp build pdu iovec(). Attack vectors include sending H2C DATA PDUs before a CONNECT command, sending H2C DATA PDUs for READ commands, or utilizing uninitialized command slots.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

LPE

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:2264
ALSA-2026:2378
ALSA-2026:2721
ALSA-2026:2722
AZL-78482
BDU:2026-01133
CVE-2026-22998
ECHO-3A49-CFC0-B27E
OESA-2026-1341
OESA-2026-1759
OESA-2026-1760
OESA-2026-1761
OPENSUSE-SU-2026:20416-1
RHSA-2026:2264
RHSA-2026:2378
RHSA-2026:2721
RHSA-2026:2722
SUSE-SU-2026:0962-1
SUSE-SU-2026:1078-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:20667-1
SUSE-SU-2026:20720-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21284-1
USN-8162-1
USN-8180-1
USN-8180-2
USN-8180-3
USN-8180-4
USN-8180-5
USN-8180-6
USN-8186-1
USN-8187-1
USN-8188-1
USN-8243-1
USN-8275-1
USN-8278-1
USN-8278-2
USN-8289-1
USN-8289-2
USN-8296-1
USN-8296-2
USN-8297-1
USN-8393-1
USN-8440-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu