Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-64321
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a reference count leak in nvmet_rdma_queue_connect() in the nvme target rdma component when handling queue connect requests while the host queue backlog is exceeded. A remote attacker can send connection requests that trigger the busy return path to cause a denial of service.