CVE-2026-52989: Linux Kernel

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers Currently, when nvmet_tcp_build_pdu_iovec() detects an out-of-bounds PDU length or offset, it triggers nvmet_tcp_fatal_error(cmd->queue) and returns early. However, because the function returns void, the callers are entirely unaware that a fatal error has occurred and that the cmd->recv_msg.msg_iter was left uninitialized. Callers such as nvmet_tcp_handle_h2c_data_pdu() proceed to blindly overwrite the queue state with queue->rcv_state = NVMET_TCP_RECV_DATA Consequently, the socket receiving loop may attempt to read incoming network data into the uninitialized iterator. Fix this by shifting the error handling responsibility to the callers.

Affected products

  • Linux Linux Kernel: from 5.10.250, before 5.11 (fixed in 5.11); from 5.15.200, before 5.16 (fixed in 5.16); from 6.1.163, before 6.1.175 (fixed in 6.1.175); from 6.6.124, before 6.6.141 (fixed in 6.6.141); from 6.12.70, before 6.12.91 (fixed in 6.12.91); from 6.18.10, before 6.18.33 (fixed in 6.18.33); …

Published 2026-06-24. Last modified 2026-08-21.