SB2026092533 - Use of uninitialized resource in Linux kernel nvme host driver
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of uninitialized resource (CVE-ID: CVE-2026-97409)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disable locking correctness validation.
The vulnerability exists due to use of an uninitialized resource in __nvme_fc_abort_outstanding_ios() when error recovery aborts outstanding requests before the I/O tagset is initialized. A local user can trigger an admin request timeout during controller connection to disable locking correctness validation.
The condition occurs while the NVMe over Fibre Channel controller is in the CONNECTING state.
Remediation
Install update from vendor's website.