CVE-2026-46105
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Limit NVMe request size to 2 MiB The HBA firmware reports NVMe MDTS values based on the underlying drive capability. However, because the driver allocates a fixed 4K buffer for the PRP list, accommodating at most 512 entries, the driver supports a maximum I/O transfer size of 2 MiB. Limit max_hw_sectors to the smaller of the reported MDTS and the 2 MiB driver limit to prevent issuing oversized I/O that may lead to a kernel oops.
- Affected products
- Linux Kernel, Opensuse Tumbleweed
- Linux Linux Kernel
- < 6.18.30, 7.0.7, 7.1
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.1% (3th percentile)
- NVD status
- Analyzed
- Published
- 2026-05-28
No indexed exploits for CVE-2026-46105 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-46105 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.