{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  nvme-tcp: check the data direction of a C2HData PDU  nvme_tcp_handle_c2h_data() finds the request by command id and checks that it has a payload, but it does not check that the command asked for data to be read.  A controller that answers a write command with C2HData therefore reaches nvme_tcp_recv_data(), where _copy_to_iter() hits WARN_ON_ONCE(i-\u003edata_source) and returns 0.  The receive path turns that into -EFAULT and resets the controller.  No data is copied, so this is not memory corruption.  What a controller gets is a kernel warning it can raise at will, which is fatal on a host booted with panic_on_warn.  The send path already knows the direction - it consults rq_data_dir() when it builds a command - and nvme_tcp_handle_r2t() checks the length and the offset of the request it names.  The C2HData path does not check the direction at all.  Reject a C2HData PDU whose command is not a read.  Rejecting it fails the command and resets the controller, as the neighbouring check in this function does; what goes away is the warning.    [    6.885580] ------------[ cut here ]------------   [    6.886457] WARNING: lib/iov_iter.c:193 at _copy_to_iter+0x289/0x1330, CPU#0: kworker/0:1H/71   [    6.888137] CPU: 0 UID: 0 PID: 71 Comm: kworker/0:1H Not tainted 7.2.0-rc5-NVMETCP-gf5098b6bae76 #1 PREEMPT(lazy)   [    6.891165] Workqueue: nvme_tcp_wq nvme_tcp_io_work   [    6.891875] RIP: 0010:_copy_to_iter+0x289/0x1330   [    6.903739] Call Trace:   [    6.904085]  \u003cTASK\u003e   [    6.909254]  __skb_datagram_iter+0x433/0x820   [    6.911026]  skb_copy_datagram_iter+0x37/0x120   [    6.911622]  nvme_tcp_recv_skb+0xa07/0x4320   [    6.913378]  __tcp_read_sock+0x1ab/0x810   [    6.915788]  nvme_tcp_try_recv+0x152/0x1e0   [    6.918222]  nvme_tcp_io_work+0x1e4/0x6c0   [    6.926906]  \u003c/TASK\u003e   [    6.927226] ---[ end trace 0000000000000000 ]---   [    6.927878] nvme nvme0: queue 1 failed to copy request 0x71 data   [    6.928709] nvme nvme0: receive failed:  -14",
  "id": "DEBIAN-CVE-2026-89973",
  "modified": "2026-09-17T04:47:36.598248891Z",
  "published": "2026-09-16T11:17:08.057Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89973"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89973"
  ]
}