SB2026092843 - Missing Release of Resource after Effective Lifetime in Linux kernel nvme target driver
Published: September 28, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-98152)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of resources in the nvmet_rdma_queue_connect function when handling an RDMA connection while pending disconnecting queues exceed the backlog limit. A remote attacker can initiate a connection under this condition to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/186414a6a1a34e081b07e8873622f90402346235
- https://git.kernel.org/stable/c/287420cde9d6669abcd2878c344db67423eb7df6
- https://git.kernel.org/stable/c/32e598324edc3ebb1ac9362d5b9fc30ce0de4873
- https://git.kernel.org/stable/c/4f7cf573cdf0ee857448b9b1967d686b07c71e7d
- https://git.kernel.org/stable/c/60d56bf0b14d3c545bacb9aeef92a7e6f2cf0caa
- https://git.kernel.org/stable/c/e48f9d1076f8c62c3969588d638602b94aaeff12
- https://git.kernel.org/stable/c/fb1ed67788e21832b614c23767a088c08cfdd2f2