Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-80821
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource release in nvmet_pci_epf_create_cq() when processing Create IO completion queue commands with a failing PRP1 or pci_addr mapping. A remote attacker can issue crafted Create IO CQ commands to cause a denial of service.
A too-small partial PCI address-space mapping can also trigger the issue.