SB20260916145 - Use-after-free in Linux kernel nvme target driver



SB20260916145 - Use-after-free in Linux kernel nvme target driver

Published: September 16, 2026

Security Bulletin ID SB20260916145
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Use-after-free (CVE-ID: CVE-2026-89970)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper synchronization of delayed work in the NVMe target authentication submission queue teardown logic when an authentication timeout callback runs during submission queue teardown. A remote attacker can cause the authentication timeout work to race with submission queue teardown to compromise confidentiality, integrity, and availability.


Remediation

Install update from vendor's website.