SB20260916145 - Use-after-free in Linux kernel nvme target driver
Published: September 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-89970)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper synchronization of delayed work in the NVMe target authentication submission queue teardown logic when an authentication timeout callback runs during submission queue teardown. A remote attacker can cause the authentication timeout work to race with submission queue teardown to compromise confidentiality, integrity, and availability.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/664022fa1c93f4eba09ef5ee02411b9709dd7a93
- https://git.kernel.org/stable/c/7555ddd60af72df2862dd8f9b730a9848577edda
- https://git.kernel.org/stable/c/c17c87bde6d6f5252a6a6f0a94b2430164aa28d5
- https://git.kernel.org/stable/c/c3c126a6142a1335bc8c34a5607c39cf01daf295
- https://git.kernel.org/stable/c/eaa948c0e19b1bb2d93262207bca0c3d19cc3406
- https://git.kernel.org/stable/c/eb4f9127a2b8a152743f1ee597627e2f69cb54fe