Back

HIGH

Kernel: null pointer dereference in nvmet_tcp_execute_request

Published Feb 7, 2024

Description

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial of service.

Affected products

Remediation

Vendor solution

To mitigate this issue, prevent module nvmet-tcp from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

Red Hat statement

Red Hat Enterprise Linux 6 and 7 are not affected by this issue as it doesn't ship the related NVMe driver code.

Red Hat mitigation

To mitigate this issue, prevent module nvmet-tcp from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 7, 2024
Updated Nov 6, 2025
Reserved Dec 5, 2023
CISA Vulnrichment
Updated Feb 8, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 11, 2023