UNKNOWN NVD
CVE-2026-80813
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist() When a host issues
In the Linux kernel, the following vulnerability has been resolved:
nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
When a host issues an Identify command with CNS 07h (Active Namespace ID
List for a specific I/O Command Set), nvmet_execute_identify_nslist() is
called with match_css set. The command-set filter dereferences req->ns,
but this handler never calls nvmet_req_find_ns(), so req->ns is always
NULL (nvmet_req_init() resets it to NULL). As soon as an enabled
namespace with an NSID greater than the requested value exists,
req->ns->csi dereferences a NULL pointer and oopses.
Besides the crash, the comparison is logically wrong: to filter the list
by command set it must test the command set of the namespace being
iterated, not a single fixed value. Use the loop variable ns->csi.
References
- https://git.kernel.org/stable/c/123d664ac98d6f3464462ad4a530474b91ba9890
- https://git.kernel.org/stable/c/2bc1e33ff6a558c8ceef7c0077f3ef70a15fcba2
- https://git.kernel.org/stable/c/61dc1a37e04d4003a19095f54883358330034a39
- https://git.kernel.org/stable/c/79aba4c9403419d822972d2851f2a96a2c0531cf
This unknown severity vulnerability was published on 2026-09-04 via NVD.
vulnfeed aggregates 10236 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.