External risk intelligence

Linux Kernel NVMe Target Heap Out-of-Bounds Read

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-90230

The vulnerability exists in the Linux kernel NVMe target (nvmet) authentication negotiation. While it involves network communication, NVMe over Fabrics is typically deployed in private, internal storage area networks or data center fabrics rather than directly exposed to the public internet.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a resolved vulnerability within the Linux kernel's NVMe target authentication process. The issue could allow a malicious or improperly configured host to read beyond allocated memory, potentially impacting system stability. The primary concern is confirming if this specific authentication mechanism is in use within your environment.

  • Authentication flaw in Linux kernel's storage interface.
  • Matters if your systems use NVMe target authentication.
  • Confirm if this specific feature is active.

Attack Path

How an attacker could exploit the issue

An attacker could trigger this vulnerability by sending a specially crafted authentication request to a system using the Linux kernel's NVMe target feature. This request would exploit flaws in how the kernel handles authentication data, leading to an out-of-bounds read in memory. If successful, this could allow the attacker to gain unauthorized access to sensitive information or disrupt system operations.

  • Network access required.
  • Malicious authentication request triggers vulnerability.
  • Memory corruption leads to data exposure.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the Linux kernel's NVMe target authentication could allow a malicious or non-conformant host to read past the end of an allocated buffer. This occurs when the reported transfer length or hash/DH group identifiers are not properly validated, potentially leading to unexpected service behavior.

  • Kernel memory could be read.
  • Malicious host could send crafted authentication data.
  • Uncontrolled memory access leading to instability.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Linux kernel's NVMe target (nvmet) authentication mechanism is susceptible to a heap out-of-bounds read. This vulnerability is likely to be addressed by the Linux kernel development team, with potential oversight from platform or infrastructure teams responsible for managing the kernel versions and deployments. The initial focus should be on identifying all systems utilizing the affected kernel component, assessing their exposure, and then planning remediation, which may involve kernel updates during scheduled maintenance windows.

  • Kernel developers should own the fix.
  • Verify all Linux kernel deployments.
  • Plan kernel updates and deployments.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel nvmet component?

The nvmet component is the NVMe target subsystem within the Linux kernel. It allows a Linux server to act as a storage device, enabling other systems, called hosts, to connect and access storage resources over a network fabric using the NVMe protocol.

What does heap out-of-bounds read mean for CVE-2026-90230?

This weakness occurs when software reads data past the end of an intended memory buffer. In this CVE, the kernel fails to validate the size of incoming authentication data, allowing a host to trick the system into accessing memory locations it should not reach, potentially causing system instability or leaking information.

How can an attacker trigger this vulnerability?

An attacker initiates this by sending a malformed authentication request to the NVMe target. The vulnerability is triggered when the host provides deceptive values for the transfer length or identifier counts. Simply having an NVMe target service running is not enough; the attacker must actively participate in the authentication negotiation process with specially crafted data.

Do I need to worry if my NVMe target is internal?

Halo Surface Signal indicates that while this is a network-based issue, it is considered unlikely to affect public-facing systems. Because NVMe over Fabrics is typically used in isolated, private data center storage networks, the risk is generally limited to environments where untrusted hosts have network access to your storage target.

When should I prioritize patching for this vulnerability?

Start by identifying systems that have NVMe target authentication enabled. Since this requires kernel-level changes, coordinate with your infrastructure team to plan updates during your regular maintenance windows. Prioritize systems that communicate with hosts you do not fully control or trust.

References