CVE-2026-22998 is a NULL pointer dereference vulnerability in the Linux kernel NVMe-over-TCP target implementation. The H2C_DATA processing function nvmet_tcp_handle_h2c_data_pdu() validates transfer tags and data offsets but does not ensure that cmd->req.sg and cmd->iov are initialized before nvmet_tcp_build_pdu_iovec() dereferences them. An H2C_DATA PDU sent immediately after the ICREQ/ICRESP handshake, before CONNECT, can encounter two NULL pointers. PDUs associated with READ commands encounter an allocated cmd->req.sg but a NULL cmd->iov; PDUs targeting uninitialized command slots encounter two NULL pointers. These conditions can trigger a kernel panic and denial of service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel NVMe/TCP target vulnerability caused by processing H2C_DATA PDUs without validating that cmd->req.sg and cmd->iov are initialized. An unauthenticated remote attacker can trigger NULL pointer dereferences and a kernel crash, causing denial of service. The flaw also affects READ commands and uninitialized command slots. The reported CVSS v3 base score is 7.5, with availability impact but no confidentiality or integrity impact.
A remotely triggerable denial-of-service vulnerability in the Linux kernel's NVMe/TCP target implementation. Improper validation of command data structures allows unauthenticated network attackers to trigger NULL pointer dereferences using H2C_DATA PDUs, potentially causing a kernel panic. The listed CVSS v3 base score is 7.5. The fix validates both pointers before processing and is available in the referenced Echo linux package version 6.1.162-1 or later.
Vulnerability referenced by the advisory; no individual description is provided.
A Linux kernel nvme-tcp vulnerability involving NULL pointer dereferences in nvmet_tcp_build_pdu_iovec.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.