Prior report for the nvmet-tcp unbounded SGL length fix in 7.3

Greg Kroah-Hartman gregkh at linuxfoundation.org
Tue Aug 25 01:13:00 PDT 2026


On Mon, Aug 24, 2026 at 02:18:44PM -0400, Shivam Kumar wrote:
> On Mon, Aug 24, 2026 at 12:54 PM Greg Kroah-Hartman
> <gregkh at linuxfoundation.org> wrote:
> >
> > On Mon, Aug 24, 2026 at 12:07:28PM -0400, Shivam Kumar wrote:
> > > Hi Greg,
> > >
> > > Just the CVE, if one is assigned to 4a3f002, being recorded as the
> > > reporter would be all I'm after.
> >
> > We do not have names/reporters on CVEs at all, we rely on the git commit
> > text, but also will be glad to link to any external documentation as a
> > reference if needed.
> >
> > But I think you got the git id there wrong...
> >
> > thanks,
> >
> > greg k-h
> 
> Understood, thanks for explaining.
> 
> A reference link would be great if a CVE is assigned. The relevant
> thread is:
> https://lore.kernel.org/all/CA+ysrS+fsJQ+4x7jHoSEX_tiYRQJC8LEhuH2stKA6Q4qSK-MWA@mail.gmail.com/
> 
> And apologies for the bad commit id, the correct one is
> 4a3f00262a044e8e15064b1a6860968bf0500bf4
> ("nvmet-tcp: bound SGL data length before allocating command buffers").

Please see:
        https://www.kernel.org/doc/html/latest/process/cve.html
for how kernel CVEs are assigned.

thanks,

greg k-h



More information about the Linux-nvme mailing list