CVE-2026-90228: nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns()
In the Linux kernel, the following vulnerability has been resolved:
nvmet: fix NULL pointer dereference in nvmetexecuteidentifynszns()
When a host issues an Identify command with CNS 05h (I/O Command Set specific Identify Namespace) and CSI 02h (ZNS) targeting a file-backed namespace, nvmetexecuteidentifynszns() calls bdeviszoned() on req->ns->bdev. A file-backed namespace has no block device, so req->ns->bdev is NULL and bdeviszoned() dereferences it, oopsing.
The I/O command set is selected by the host-supplied CSI field and the command is routed here whenever CONFIGBLKDEVZONED is enabled, independent of the namespace backing type, so any file-backed namespace is exposed.
Reject the command with Invalid Field when the namespace is not backed by a block device.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using the NVMe target subsystem with a file-backed namespace are exposed when CONFIG_BLK_DEV_ZONED is enabled. The issue is independent of the namespace backing type check because host-supplied CSI selection can route the request to the affected handler.
What does an attacker need to do to trigger the failure?
A host must issue an Identify command using CNS 05h and CSI 02h (ZNS) against a file-backed namespace. This causes the target to call bdev_is_zoned() with a NULL block-device pointer and oops.
What behavior indicates that the fix is present?
For a file-backed namespace, the affected Identify request should be rejected with Invalid Field rather than causing an oops.