Back

HIGH

nvmet-tcp: fix kernel crash if commands allocation fails

Published Sep 18, 2024

Description

If the commands allocation fails in nvmet_tcp_alloc_cmds() the kernel crashes in nvmet_tcp_release_queue_work() because of a NULL pointer dereference.

nvmet: failed to install queue 0 cntlid 1 ret 6 Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008

Fix the bug by setting queue->nr_cmds to zero in case nvmet_tcp_alloc_cmd() fails.

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, prevent the `nvmet-tcp` kernel module from loading. This can be achieved by blacklisting the module. 1. Create a new file `/etc/modprobe.d/blacklist-nvmet-tcp.conf` with the following content: ``` blacklist nvmet_tcp ``` 2. Rebuild the `initramfs` to ensure the blacklist is applied during boot: ```bash dracut -f -v ``` 3. Reboot the system for the changes to take effect. This mitigation may impact systems that rely on NVMe over TCP functionality.

References (15)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Sep 18, 2024
Updated Aug 5, 2026
Reserved Sep 11, 2024

CISA Vulnrichment

Updated Sep 29, 2024

NVD

Status Modified
Modified Aug 4, 2026

Red Hat

Severity Moderate
Public date Sep 18, 2024
Bugzilla 2313085

ENISA EUVD

Assigner Linux
Published Sep 18, 2024
Updated Aug 5, 2026

GitHub

No data