Race condition in Linux kernel - CVE-2026-46135
Published: May 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in nvmet_tcp_handle_icreq() and target-side queue teardown when processing an initialization connection request and a connection close concurrently. A remote attacker can send an initialization connection request and immediately close the connection to cause a denial of service.
The issue can lead to a second kref_put() being issued on an already released queue.
Affected software
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Ubuntu
openEuler
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel (Red Hat package)
kernel-rt (Red Hat package)
kernel
kernel-doc
kernel-abi-stablelists
python3-perf
perf
kernel-tools-libs-devel
kernel-tools-libs
kernel-tools
kernel-modules-extra
kernel-modules
kernel-devel
kernel-debug-modules-extra
kernel-debug-modules
kernel-debug-devel
kernel-debug-core
kernel-debug
kernel-cross-headers
kernel-core
bpftool
kernel-headers
linux (Ubuntu package)
linux-ibm (Ubuntu package)
linux-raspi (Ubuntu package)
kernel-tools-debuginfo
python3-perf-debuginfo
kernel-tools-devel
perf-debuginfo
bpftool-debuginfo
kernel-source
kernel-debugsource
kernel-debuginfo
linux-xilinx-zynqmp (Ubuntu package)
linux-gcp-5.15 (Ubuntu package)
linux-oracle-5.15 (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-raspi-realtime (Ubuntu package)
linux-hwe-6.17 (Ubuntu package)
linux-azure-fde-6.17 (Ubuntu package)
linux-azure-6.17 (Ubuntu package)
linux-nvidia-6.17 (Ubuntu package)
linux-oem-6.17 (Ubuntu package)
linux-nvidia (Ubuntu package)
How to mitigate CVE-2026-46135
kernel (Red Hat package) - addressed in versions 4.18.0-305.199.1.el8_4, 4.18.0-372.201.1.el8_6, 4.18.0-553.136.1.el8_10, 5.14.0-284.179.1.el9_2, 5.14.0-427.139.1.el9_4, 5.14.0-570.127.1.el9_6, 5.14.0-687.17.1.el9_8, 6.12.0-55.88.1.el10_0, 6.12.0-211.28.1.el10_2
kernel-rt (Red Hat package) - addressed in versions 4.18.0-553.136.1.rt7.477.el8_10, 5.14.0-284.179.1.rt14.464.el9_2
kernel - update to 4.18.0-553.137.1.0.1
kernel-doc - update to 4.18.0-553.137.1.0.1
kernel-abi-stablelists - update to 4.18.0-553.137.1.0.1
python3-perf - update to 4.18.0-553.137.1.0.1
perf - update to 4.18.0-553.137.1.0.1
kernel-tools-libs-devel - update to 4.18.0-553.137.1.0.1
kernel-tools-libs - update to 4.18.0-553.137.1.0.1
kernel-tools - update to 4.18.0-553.137.1.0.1
kernel-modules-extra - update to 4.18.0-553.137.1.0.1
kernel-modules - update to 4.18.0-553.137.1.0.1
kernel-devel - update to 4.18.0-553.137.1.0.1
kernel-debug-modules-extra - update to 4.18.0-553.137.1.0.1
kernel-debug-modules - update to 4.18.0-553.137.1.0.1
kernel-debug-devel - update to 4.18.0-553.137.1.0.1
kernel-debug-core - update to 4.18.0-553.137.1.0.1
kernel-debug - update to 4.18.0-553.137.1.0.1
kernel-cross-headers - update to 4.18.0-553.137.1.0.1
kernel-core - update to 4.18.0-553.137.1.0.1
bpftool - update to 4.18.0-553.137.1.0.1
kernel-headers - update to 4.18.0-553.137.1.0.1
linux (Ubuntu package) - addressed in versions 5.4.0.233.225, 5.4.0-233.253, 5.4.0-233.253~18.04.1, 5.4.0-1065.68, 5.4.0.1079.79, 5.4.0-1079.83, 5.4.0.1120.116, 5.4.0-1120.127, 5.4.0.1135.132, 5.4.0-1135.145, 5.4.0.1159.153, 5.4.0-1159.169+fips1, 5.4.0-1159.169~18.04.1, 5.4.0.1161.108, 5.4.0.1161.159, 5.4.0-1161.172, 5.4.0-1161.172+fips1, 5.4.0-1161.172~18.04.1, 5.4.0.1164.106, 5.4.0.1164.166, 5.4.0-1164.173, 5.4.0-1164.173+fips1, 5.4.0-1164.173~18.04.1, 5.4.0.1166.102, 5.4.0.1166.158, 5.4.0-1166.172, 5.4.0-1166.172+fips1, 5.4.0-1166.172~18.04.1, 5.15.0.183.154, 5.15.0-183.193, 5.15.0-183.193~20.04.1, 5.15.0.185.108, 5.15.0.185.166, 5.15.0-185.195+fips1, 5.15.0-185.195~20.04.1, 5.15.0-1052.52, 5.15.0.1052.54, 5.15.0-1063.63, 5.15.0-1063.63~20.04.1, 5.15.0.1094.93, 5.15.0-1094.102, 5.15.0.1103.99, 5.15.0-1103.105, 5.15.0.1103.107, 5.15.0-1103.108, 5.15.0.1105.102, 5.15.0.1105.109, 5.15.0-1105.109~20.04.1, 5.15.0.1106.105, 5.15.0.1106.106, 5.15.0-1106.107, 5.15.0-1106.112, 5.15.0.1107.106, 5.15.0-1107.113, 5.15.0.1108.104, 5.15.0-1108.114, 5.15.0.1110.114, 5.15.0-1110.119, 5.15.0.1111.101, 5.15.0.1111.107, 5.15.0.1111.108, 5.15.0.1111.114, 5.15.0-1111.118, 5.15.0-1111.118+fips1, 5.15.0-1111.118~20.04.1, 5.15.0-1111.121, 5.15.0-1111.121+fips1, 5.15.0.1116.114, 5.15.0-1116.125, 5.15.0-1116.125~20.04.1, 6.8.0-134.134, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61+fips1, 6.8.0-1058.61~22.04.1, 6.8.0-1060.61, 6.8.0-1060.63+fips1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69, 6.8.0-1063.69+fips1, 6.8.1-1055.56, 6.8.1-1055.56~22.04.1, 6.17.0-40.40, 7.0.0-27.27
linux-ibm (Ubuntu package) - addressed in versions 5.4.0-1107.112, 5.4.0-1107.112~18.04.1, 5.4.0.1107.136
linux-raspi (Ubuntu package) - addressed in versions 5.4.0-1144.157, 5.4.0-1144.157~18.04.1, 5.4.0.1144.175, 5.15.0.1105.103, 5.15.0-1105.108, 6.8.0-1060.64, 6.17.0-1021.21, 7.0.0-1014.14
kernel-tools - update to 5.10.0-321.0.0.223
kernel-tools-debuginfo - update to 5.10.0-321.0.0.223
python3-perf-debuginfo - update to 5.10.0-321.0.0.223
kernel-tools-devel - update to 5.10.0-321.0.0.223
perf - update to 5.10.0-321.0.0.223
perf-debuginfo - update to 5.10.0-321.0.0.223
bpftool-debuginfo - update to 5.10.0-321.0.0.223
python3-perf - update to 5.10.0-321.0.0.223
kernel-source - update to 5.10.0-321.0.0.223
kernel-headers - update to 5.10.0-321.0.0.223
kernel-devel - update to 5.10.0-321.0.0.223
kernel-debugsource - update to 5.10.0-321.0.0.223
kernel-debuginfo - update to 5.10.0-321.0.0.223
kernel - update to 5.10.0-321.0.0.223
bpftool - update to 5.10.0-321.0.0.223
linux-xilinx-zynqmp (Ubuntu package) - addressed in versions 5.15.0.1074.77, 5.15.0-1074.78
linux-gcp-5.15 (Ubuntu package) - addressed in versions 5.15.0-1106.112~20.04.1, 5.15.0-1111.121~20.04.1
linux-oracle-5.15 (Ubuntu package) - update to 5.15.0-1108.114~20.04.1
linux-azure-fips (Ubuntu package) - addressed in versions 5.15.0.1116.101, 5.15.0-1116.125+fips1, 6.8.0-134.134+fips1, 6.8.0-1062.69+fips1
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1029.30
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1045.48, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61.1, 6.8.0-1058.64, 6.8.0-1060.61~22.04.1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69~22.04.1
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1, 7.0.0-1009.9, 7.0.0-1010.10
linux-raspi-realtime (Ubuntu package) - update to 6.8.0-2049.50
linux-hwe-6.17 (Ubuntu package) - update to 6.17.0-40.40~24.04.1
linux-azure-fde-6.17 (Ubuntu package) - update to 6.17.0-1018.18~24.04.1
linux-azure-6.17 (Ubuntu package) - update to 6.17.0-1021.21~24.04.1
linux-nvidia-6.17 (Ubuntu package) - update to 6.17.0-1026.26
linux-oem-6.17 (Ubuntu package) - update to 6.17.0-1028.28
linux-nvidia (Ubuntu package) - update to 7.0.0-1013.13
External References
Related Security Bulletins
- Race condition in Linux kernel nvme target driver
- Red Hat Enterprise Linux 8 update for kernel
- Red Hat Enterprise Linux 8 update for kernel-rt
- Red Hat Enterprise Linux 9 update for kernel
- Red Hat Enterprise Linux 10 update for kernel
- Anolis OS update for kernel:4.18
- Ubuntu update for linux
- Ubuntu update for linux-oem-6.17
- Ubuntu update for linux
- Ubuntu update for linux
- Ubuntu update for linux
- Ubuntu update for linux-nvidia-tegra
- Ubuntu update for linux-aws-6.8
- Ubuntu update for linux-raspi
- Ubuntu update for linux-oracle-5.15
- openEuler 22.03 LTS SP4 update for kernel
- Ubuntu update for linux-nvidia-6.17
- Ubuntu update for linux-nvidia
- Red Hat Enterprise Linux 9 update for kernel-rt
- Red Hat Enterprise Linux 9 update for kernel
- Ubuntu update for linux-raspi-realtime
- Red Hat Enterprise Linux 9 update for kernel
- Ubuntu update for linux-raspi
- Ubuntu update for linux-raspi
- Ubuntu update for linux-xilinx-zynqmp
- Ubuntu update for linux-raspi
- Ubuntu update for linux-azure-fips
- Red Hat Enterprise Linux 10 update for kernel
- Ubuntu update for linux-hwe-6.17
- Ubuntu update for linux-raspi
- Ubuntu update for linux-gcp-5.15
- Red Hat Enterprise Linux 8 update for kernel
- Red Hat Enterprise Linux 9 update for kernel
- Ubuntu update for linux-azure
- Ubuntu update for linux-azure-fde-6.8
- Ubuntu update for linux-azure-fde
- Ubuntu update for linux-azure
- Ubuntu update for linux-azure-fde-6.17
- Ubuntu update for linux-azure-6.17
- Ubuntu update for linux-ibm
- Ubuntu update for linux
- Ubuntu update for linux-azure-fips
- Ubuntu update for linux-hwe-6.8
- Red Hat Enterprise Linux 8 update for kernel
- Ubuntu update for linux-raspi