CVE-2026-23112 is an out-of-bounds access vulnerability in the Linux kernel NVMe-over-TCP target implementation. Insufficient bounds checking in nvmet_tcp_build_pdu_iovec() allows traversal beyond the request's scatter-gather array when a PDU length or offset exceeds the available entries. Invalid scatter-gather length and offset values can then be used to construct a buffer vector, triggering a general protection fault or KASAN-detected memory error in _copy_to_iter(). The fix validates the scatter-gather index, remaining entries, and entry length and offset before constructing the buffer vector.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A bounds-checking vulnerability in the Linux kernel's NVMe-over-TCP target implementation. Invalid PDU lengths or offsets can cause traversal beyond the scatter-gather array and use of invalid length or offset values, resulting in kernel faults or KASAN-detected memory errors. The listing assigns a critical CVSS v3 score of 9.8, although vendor severity is LOW. The fix validates scatter-gather indices, remaining entries, lengths, and offsets before building the buffer vector.
A critical Linux kernel NVMe over TCP (nvmet-tcp) bounds-checking flaw in nvmet_tcp_build_pdu_iovec. Malformed or excessive PDU length/offset values can cause traversal beyond the request scatter-gather array and lead to a general-protection fault or KASAN-detected memory-safety failure.
The plugin uses CVE-2026-23112 as its CVSS score source and reports no known exploits for the advisory.
A critical vulnerability covered by the EulerOS Virtualization 2.11.1 kernel security-update advisory. The advisory/plugin assigns it a CVSS v3 base score of 9.8 and indicates exploit availability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.