<?xml version="1.0" encoding="UTF-8"?>
<VrdaData refvuldefversion="1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://vrda.jpcert.or.jp" xsi:schemaLocation="http://vrda.jpcert.or.jp/feed/xsd/vrda_data.xsd">
  <VrdaDataProvider>
    <Name>JVN iPedia</Name>
    <URL>http://jvndb.jvn.jp</URL>
  </VrdaDataProvider>
  <VrdaDataSourceType>Advisory</VrdaDataSourceType>
  <Vulinfo revisionno="1" lang="ja" invalidated="false">
    <VulinfoID>JVNDB-2026-032048</VulinfoID>
    <VulinfoData>
      <Title>Linux&#12398;Linux Kernel&#12395;&#12362;&#12369;&#12427;&#22659;&#30028;&#22806;&#35501;&#12415;&#21462;&#12426;&#12395;&#38306;&#12377;&#12427;&#33030;&#24369;&#24615;</Title>
      <VulinfoDescription>
        <Overview>Linux&#12459;&#12540;&#12493;&#12523;&#12395;&#12362;&#12356;&#12390;&#12289;&#20197;&#19979;&#12398;&#33030;&#24369;&#24615;&#12364;&#20462;&#27491;&#12373;&#12428;&#12414;&#12375;&#12383;&#12290;nvmet-auth&#12395;&#38306;&#12375;&#12390;&#12289;&#36820;&#20449;&#12513;&#12483;&#12475;&#12540;&#12472;&#12398;&#12506;&#12452;&#12525;&#12540;&#12489;&#22659;&#30028;&#12434;&#36578;&#36865;&#38263;&#12392;&#29031;&#21512;&#12375;&#12390;&#26908;&#35388;&#12377;&#12427;nvmet_auth_reply()&#38306;&#25968;&#12399;&#12289;&#21106;&#12426;&#24403;&#12390;&#12425;&#12428;&#12383;&#12496;&#12483;&#12501;&#12449;&#12469;&#12452;&#12474;tl&#12496;&#12452;&#12488;&#20869;&#12395;&#21454;&#12414;&#12427;&#12363;&#12393;&#12358;&#12363;&#12434;&#26908;&#35388;&#12379;&#12378;&#12289;&#25915;&#25731;&#32773;&#12364;&#21046;&#24481;&#12377;&#12427;hl&#65288;&#12495;&#12483;&#12471;&#12517;&#38263;&#65289;&#12362;&#12424;&#12403;dhvlen&#65288;DH&#20516;&#38263;&#65289;&#12501;&#12451;&#12540;&#12523;&#12489;&#12434;&#20351;&#29992;&#12375;&#12390;&#21487;&#22793;&#38263;&#12398;rval[]&#37197;&#21015;&#12395;&#12450;&#12463;&#12475;&#12473;&#12375;&#12414;&#12377;&#12290;&#24746;&#24847;&#12398;&#12354;&#12427;NVMe-oF&#12452;&#12491;&#12471;&#12456;&#12540;&#12479;&#12399;&#12289;&#23567;&#12373;&#12394;&#36578;&#36865;&#38263;&#12395;&#23550;&#12375;&#12390;&#22823;&#12365;&#12394;hl/dhvlen&#20516;&#12434;&#25345;&#12388;DHCHAP_REPLY&#12513;&#12483;&#12475;&#12540;&#12472;&#12434;&#20316;&#25104;&#12375;&#12289;&#12479;&#12540;&#12466;&#12483;&#12488;&#12364;DH&#20844;&#38283;&#37749;&#65288;rval + 2*hl&#65289;&#12434;&#20966;&#29702;&#12375;&#12383;&#12426;&#12507;&#12473;&#12488;&#24540;&#31572;&#12398;memcmp&#12434;&#23455;&#34892;&#12375;&#12383;&#38555;&#12395;&#12498;&#12540;&#12503;&#22806;&#35501;&#12415;&#21462;&#12426;&#12434;&#24341;&#12365;&#36215;&#12371;&#12377;&#21487;&#33021;&#24615;&#12364;&#12354;&#12426;&#12414;&#12377;&#12290;DH&#35469;&#35388;&#12364;&#35373;&#23450;&#12373;&#12428;&#12390;&#12356;&#12427;&#22580;&#21512;&#12289;OOB&#12509;&#12452;&#12531;&#12479;&#12399;sg_init_one()&#12395;&#30452;&#25509;&#28193;&#12373;&#12428;&#12289;crypto_kpp_compute_shared_secret()&#12395;&#12424;&#12387;&#12390;&#35501;&#12415;&#21462;&#12425;&#12428;&#12289;&#12496;&#12483;&#12501;&#12449;&#12434;&#26368;&#22823;526&#12496;&#12452;&#12488;&#36229;&#36942;&#12375;&#12390;&#12450;&#12463;&#12475;&#12473;&#12373;&#12428;&#12414;&#12377;&#12290;&#12371;&#12398;&#33030;&#24369;&#24615;&#12399;&#35469;&#35388;&#21069;&#12391;&#12418;&#24746;&#29992;&#21487;&#33021;&#12391;&#12377;&#12290;&#21487;&#22793;&#38263;&#12501;&#12451;&#12540;&#12523;&#12489;&#12395;&#12450;&#12463;&#12475;&#12473;&#12377;&#12427;&#21069;&#12395;&#12289;sizeof(*data) + 2*hl + dhvlen &#65308;= tl&#12392;&#12356;&#12358;&#22659;&#30028;&#12481;&#12455;&#12483;&#12463;&#12434;&#36861;&#21152;&#12375;&#12414;&#12375;&#12383;&#12290;&#12371;&#12398;&#33030;&#24369;&#24615;&#12399;&#12289;Atuin&#12392;&#12356;&#12358;&#33258;&#21205;&#33030;&#24369;&#24615;&#30330;&#35211;&#12456;&#12531;&#12472;&#12531;&#12395;&#12424;&#12387;&#12390;&#30330;&#35211;&#12373;&#12428;&#12414;&#12375;&#12383;&#12290;</Overview>
      </VulinfoDescription>
      <Affected>
        <AffectedItem affectedstatus="vulnerable">
          <Lapt>cpe:/o:linux:linux_kernel</Lapt>
        </AffectedItem>
      </Affected>
      <FactAnalysis>
      </FactAnalysis>
      <Related>
        <RelatedItem relationtype="self" origin="jvnipedia">
          <URL>https://jvndb.jvn.jp/ja/contents/2026/JVNDB-2026-032048.html</URL>
        </RelatedItem>
        <RelatedItem relationtype="alternate" origin="other">
          <Name>Common Vulnerabilities and Exposures (CVE)</Name>
          <VulinfoID>CVE-2026-64319</VulinfoID>
          <URL>https://www.cve.org/CVERecord?id=CVE-2026-64319</URL>
        </RelatedItem>
        <RelatedItem relationtype="alternate" origin="other">
          <Name>National Vulnerability Database (NVD)</Name>
          <VulinfoID>CVE-2026-64319</VulinfoID>
          <URL>https://nvd.nist.gov/vuln/detail/CVE-2026-64319</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>JVNDB</Name>
          <VulinfoID>CWE-125</VulinfoID>
          <Title>&#22659;&#30028;&#22806;&#35501;&#12415;&#21462;&#12426;</Title>
          <URL>https://cwe.mitre.org/data/definitions/125.html</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>nvmet-auth: validate reply message payload bounds against transfer length - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/caa71b3a43ea5c13fe7141cb019ebcb03b8ac857)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/caa71b3a43ea5c13fe7141cb019ebcb03b8ac857</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>nvmet-auth: validate reply message payload bounds against transfer length - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/80cd28b56ab62d3e7ed0a7bf05282e6d3ee5b2a0)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/80cd28b56ab62d3e7ed0a7bf05282e6d3ee5b2a0</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>nvmet-auth: validate reply message payload bounds against transfer length - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/999f6205ede984a786f35f727b01f971b98e215d)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/999f6205ede984a786f35f727b01f971b98e215d</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>nvmet-auth: validate reply message payload bounds against transfer length - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/3a413ece2504c70aa34a20be4dafec04e8c741f9)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/3a413ece2504c70aa34a20be4dafec04e8c741f9</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>nvmet-auth: validate reply message payload bounds against transfer length - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/6d7649c1231dac14d906985d2936967e23041c26)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/6d7649c1231dac14d906985d2936967e23041c26</URL>
        </RelatedItem>
      </Related>
      <DateFirstPublished>2026-09-04T17:50:20+09:00</DateFirstPublished>
      <DateLastUpdated>2026-09-04T17:50:20+09:00</DateLastUpdated>
    </VulinfoData>
  </Vulinfo>
</VrdaData>
