cbcvebase.
CVE-2026-23112
published 2026-02-13

CVE-2026-23112: In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could…

PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.40%
32.2th percentile
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU length or offset exceeds sg_cnt and then use bogus sg->length/offset values, leading to _copy_to_iter() GPF/KASAN. Guard sg_idx, remaining entries, and sg->length/offset before building the bvec.

Affected

96 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= 872d26a391da92ed8f0c0f5cb5fef428067b7f30 < 0b9981751be14b59b4473383c731c833738aebdb0b9981751be14b59b4473383c731c833738aebdb
linuxlinux>= 872d26a391da92ed8f0c0f5cb5fef428067b7f30 < 42afe8ed8ad2de9c19457156244ef3e1eca94b5d42afe8ed8ad2de9c19457156244ef3e1eca94b5d
linuxlinux>= 872d26a391da92ed8f0c0f5cb5fef428067b7f30 < 1385be357e8acd09b36e026567f3a9d5c61139de1385be357e8acd09b36e026567f3a9d5c61139de
linuxlinux>= 872d26a391da92ed8f0c0f5cb5fef428067b7f30 < dca1a6ba0da9f472ef040525fab10fd9956db59fdca1a6ba0da9f472ef040525fab10fd9956db59f
linuxlinux>= 872d26a391da92ed8f0c0f5cb5fef428067b7f30 < 19672ae68d52ff75347ebe2420dde1b07adca09f19672ae68d52ff75347ebe2420dde1b07adca09f
linuxlinux>= 872d26a391da92ed8f0c0f5cb5fef428067b7f30 < ab200d71553bdcf4de554a5985b05b2dd606bc57ab200d71553bdcf4de554a5985b05b2dd606bc57
linuxlinux>= 872d26a391da92ed8f0c0f5cb5fef428067b7f30 < 52a0a98549344ca20ad81a4176d68d28e3c05a5c52a0a98549344ca20ad81a4176d68d28e3c05a5c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.251-15.10.251-1
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 5.0 < 5.10.2505.10.250
linuxlinux_kernel>= 5.11 < 5.15.2005.15.200
linuxlinux_kernel>= 5.16 < 6.1.1636.1.163
linuxlinux_kernel>= 6.13 < 6.18.106.18.10
linuxlinux_kernel>= 6.2 < 6.6.1246.6.124
linuxlinux_kernel>= 6.7 < 6.12.706.12.70
ubuntuaws
ubuntuaws-5.15
ubuntuaws-6.8
ubuntuazure

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.