SB20260918265 - Missing Release of Resource after Effective Lifetime in Linux kernel nvme host driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-90411)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a DMA mapping resource leak.
The vulnerability exists due to improper resource cleanup in __nvme_fc_init_request() when handling a response IU DMA mapping failure. A local user can trigger request initialization with a response IU DMA mapping failure to cause a DMA mapping resource leak.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/18c5781ed8bc2f423c26ec93e47e2057cd76a783
- https://git.kernel.org/stable/c/5e820d04c241c81a47e1940349018690e93d8167
- https://git.kernel.org/stable/c/acc173608ca7abe5dee8983086b44efd8b0dbc84
- https://git.kernel.org/stable/c/bb0251991420c25e3ceeac40ea09250d79ed7ef0
- https://git.kernel.org/stable/c/bd764baf82bb46e958a0bd0b481630dd71313055
- https://git.kernel.org/stable/c/be5eb47ee3fea338efae1a5b678d6bb5f0fcc931
- https://git.kernel.org/stable/c/c0892cfb60a75e2c86ba8e2127b133f6549c12b3
- https://git.kernel.org/stable/c/f49d0c3a8d56a7cda1628ae17341a4a42063563c