Double free in Linux kernel - CVE-2026-89974

 

Double free in Linux kernel - CVE-2026-89974

Published: September 16, 2026


Vulnerability identifier: #VU150308
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89974
CWE-ID: CWE-415
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to a double free in the nvme-fc controller initialization and cleanup logic when nvme_add_ctrl() fails during controller creation. A remote attacker can trigger the affected error path to compromise confidentiality, integrity, and availability.

The failure is reachable under memory pressure or fault injection.


Affected software

Linux kernel

How to mitigate CVE-2026-89974

Install security update from vendor's repository.


External References

Related Security Bulletins