[PATCH] nvme-tcp: fix host memory disclosure on R2T for a read command

Keith Busch kbusch at kernel.org
Mon Aug 10 17:39:11 PDT 2026


On Wed, Jul 29, 2026 at 02:46:02PM +0900, Yehyeong Lee wrote:
> nvme_tcp_handle_r2t() does not check the direction of the request the
> R2T refers to. A malicious controller can send an R2T for a READ and
> the host will answer it: nvme_tcp_setup_h2c_data_pdu() builds the
> H2CData header and nvme_tcp_try_send_data() sends the request's data
> buffer. That buffer is the READ destination, so its contents go to the
> controller.
> 
> The command then completes normally and nothing is logged.
> 
> Against a test controller that answers every READ with an R2T, a 4096
> byte buffered read returned all 4096 bytes, split over two R2Ts. The
> pages contained stale kernel data, including an array of struct page
> pointers.
> 
> Reject an R2T for a request that is not a write.

Looks good to me. Applied to nvme-7.3.



More information about the Linux-nvme mailing list