Home

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Limit NVMe request size to 2 MiB The HBA firmware reports NVMe MDTS values based on the underlying drive capability. However, because the driver allocates a fixed 4K buffer for the PRP list, accommodating at most 512 entries, the driver supports a maximum I/O transfer size of 2 MiB. Limit max_hw_sectors to the smaller of the reported MDTS and the 2 MiB driver limit to prevent issuing oversized I/O that may lead to a kernel oops.

PUBLISHED Reserved 2026-05-13 | Published 2026-05-28 | Updated 2026-05-30 | Assigner Linux




HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Product status

Default status
unaffected

9b8b84879d4adc506b0d3944e20b28d9f3f6994b (git) before 45dcc815fc5539e88154315f36cbcb11d3a52fc2
affected

9b8b84879d4adc506b0d3944e20b28d9f3f6994b (git) before e5f9824817c6358b9f9738bdb92dec9e4e794d3c
affected

9b8b84879d4adc506b0d3944e20b28d9f3f6994b (git) before 04631f55afc543d5431a2bdee7f6cc0f2c0debe7
affected

Default status
affected

6.17
affected

Any version before 6.17
unaffected

6.18.30 (semver)
unaffected

7.0.7 (semver)
unaffected

7.1-rc3 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/45dcc815fc5539e88154315f36cbcb11d3a52fc2

git.kernel.org/...c/e5f9824817c6358b9f9738bdb92dec9e4e794d3c

git.kernel.org/...c/04631f55afc543d5431a2bdee7f6cc0f2c0debe7

cve.org (CVE-2026-46105)

nvd.nist.gov (CVE-2026-46105)

Download JSON