Back

CRITICAL

nvmet-rdma: handle inline data with a nonzero offset

Published Aug 15, 2026

Description

nvmet_rdma_use_inline_sg() maps the host-controlled inline data offset into the per-command inline scatterlist. The bounds check admits any offset with off + len <= inline_data_size, but the mapping still assumes the data begins in the first inline page:

sg->offset = off; sg->length = min_t(int, len, PAGE_SIZE - off);

When a port is configured with inline_data_size > PAGE_SIZE (settable up to max(SZ_16K, PAGE_SIZE)), an offset in (PAGE_SIZE, inline_data_size] makes "PAGE_SIZE - off" underflow, so sg->length is set to ~4 GiB and the block backend reads far past the first inline page. num_pages(len) also ignores the offset, so an in-bounds offset whose [off, off+len) span crosses a page boundary under-counts the scatterlist.

Map the offset properly: split it into a page index and an in-page offset, start the scatterlist at that page, and size the page count from page_off + len. Because the request scatterlist may now start at inline_sg[page_idx] rather than inline_sg[0], generalize the inline-SGL identity test in nvmet_rdma_release_rsp() to a range test; otherwise the persistent inline scatterlist is mistaken for an allocated one and nvmet_req_free_sgls() frees an inline page (and warns in free_large_kmalloc()).

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, prevent the `nvmet_rdma` kernel module from loading if NVMe over RDMA functionality is not required. This can be achieved by creating a modprobe configuration file. 1. Create a file named `/etc/modprobe.d/disable-nvmet_rdma.conf` with the following content: ``` install nvmet_rdma /bin/true ``` 2. Regenerate the initramfs to ensure the change takes effect on boot: ```bash dracut -f -v ``` 3. Reboot the system for the changes to be fully applied. This mitigation may impact systems that rely on NVMe over RDMA for storage operations. If NVMe over RDMA is in use, consider configuring `inline_data_size` to be less than or equal to `PAGE_SIZE` if your workload permits, though this might affect performance.

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Aug 15, 2026
Updated Aug 17, 2026
Reserved Aug 9, 2026
NVD
Status Received
Modified Aug 17, 2026
Red Hat
Severity Important
Public date Aug 15, 2026
ENISA EUVD
Assigner Linux
Published Aug 15, 2026
Updated Aug 17, 2026
Exploited since n/a
EUVD-2026-58887